---
title: "How to Secure Ansible Playbooks with Ansible Become"
description: "Learn how to secure your Ansible playbooks in this step-by-step tutorial by declaring directives, such as Ansible become!"
canonical: "https://adamtheautomator.com/ansible-become/"
---

# How to Secure Ansible Playbooks with Ansible Become

> Learn how to secure your Ansible playbooks in this step-by-step tutorial by declaring directives, such as Ansible become!

Source: https://adamtheautomator.com/ansible-become/

---

ATA Learning

Tap to hide

[

ATA Learning

](/)

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Search for:  

*   [](https://twitter.com/adbertram)
*   [](https://github.com/Adam-the-Automator)
*   [](https://www.linkedin.com/company/adam-the-automator-llc)
*   [](/feed/)

![How to Secure Ansible Playbooks with Ansible Become](https://adamtheautomator.com/wp-content/uploads/2022/02/How-to-Secure-Ansible-Playbooks-with-Ansible-Become.jpg)

# How to Secure Ansible Playbooks with Ansible Become

[![](https://secure.gravatar.com/avatar/2beb65fca997135120ed98dc6a2e57dcdf1a7d7d2f5ff687b5d91dc7ccd7a6b5?s=192&d=mm&r=g)Sagar](https://adamtheautomator.com/author/shanky-mendiratta/)9 February 20225 min. read

Categories: [DevOps](/category/devops/)

Tags:[Ansible](/tag/ansible/)[Security](/tag/security/)

Table of Contents

*   [Prerequisites](#prerequisites)
*   [Running Ansible Ad Hoc Commands with Ansible Become](#running-ansible-ad-hoc-commands-with-ansible-become)
*   [Running Ansible Playbooks with Ansible become](#running-ansible-playbooks-with-ansible-become)
*   [Working with Ansible become with Connection Variables](#working-with-ansible-become-with-connection-variables)
*   [Conclusion](#conclusion)

If you need to run commands on multiple machines with different users, then nothing could be better than using [Ansible `become`](https://docs.ansible.com/ansible/latest/user_guide/become.html). Ansible `become` allows you to become another user to deploy or manage the remote nodes, regardless of which user you’re logged into.

In this tutorial, you’ll learn how to work with Ansible become directives, Ansible `become` variables, and how to declare them in the Ansible playbook.

Read on and start securing your playbooks!

## Prerequisites

This tutorial comprises step-by-step instructions. If you’d like to follow along, be sure you have the following in place:

*   An [Ansible controller host](https://docs.ansible.com/ansible/latest/installation_guide/index.html) – This tutorial uses [Ansible v2.11.7](https://docs.ansible.com/ansible/latest/installation_guide/intro_installation.html) on an Ubuntu 20.04.3 LTS machine.

Related:[How to Setup Ansible (Ubuntu, RHEL, CentOS, macOS)](https://adamtheautomator.com/install-ansible/)

*   A remote Linux computer to test the tomcat installation – This tutorial uses Ubuntu 20.04.3 LTS as the remote node.
*   An already user-created and Apache service installed on the remote node – This tutorial demonstrates a user named Shankym.
*   An [inventory file](https://docs.ansible.com/ansible/latest/user_guide/intro_inventory.html) and one or more hosts are configured to run Ansible commands and playbooks – The remote Linux computer is called _myserver,_ and this tutorial uses an inventory group called _web_.
*   Python v3.6 or later installed both on your Ansible controller host and the remote node machine – This tutorial uses [Python v3.9](https://adamtheautomator.com/install-python-36/) on an Ubuntu machine.

Related:[How Do You Install Python 3.6?](https://adamtheautomator.com/install-python-36/)

## Running Ansible Ad Hoc Commands with Ansible Become

Do you need an urgent security fix to deploy and restart the SSH service? Running ad hoc commands will do the trick. Ad hoc commands are a quick way to run a single command on a remote host and deploy the specified changes.

Related:[How to SSH into Docker Containers \[Step-by-Step\]](https://adamtheautomator.com/ssh-into-docker-container/)

Open the terminal on your Ansible controller host, and run the `ansible` command below to connect to the host called `web` using the [_ansible.builtin.service_](https://docs.ansible.com/ansible/latest/collections/ansible/builtin/service_module.html) module (`-m`).

The command passes an argument (`-a`) that lets Ansible restart the (`apache`) service on the remote node you specified in the command.

```bash
ansible web -m ansible.builtin.service -a "name=apache2 state=restarted" --become
```

> _If you wish for the Ansible ad hoc command to prompt you for a password, then consider using the `-ask-become-pass` command instead of just the `--become` parameter_.

Once the command completes, you’ll see a **CHANGED** message, as shown below. The output below confirms Ansible successfully restarted the apache service on the remote host.

![Restarting the Apache service on the Remote Node](https://adamtheautomator.com/wp-content/uploads/2022/02/image-114.png)

Restarting the Apache service on the Remote Node

Now run the below command to check the status of the apache service using other users (`shankym`) with the `--become-user` parameter.

```bash
ansible web -m ansible.builtin.service -a "name=apache2 state=restarted" --become-user=shankym
```

![Checking the Apache service on the Remote Node as Another User (shankym)](https://adamtheautomator.com/wp-content/uploads/2022/02/image-115.png)

Checking the Apache service on the Remote Node as Another User (shankym)

## Running Ansible Playbooks with Ansible `become`

In the previous section, you learned how to use Ansible ad hoc commands to fix or restart the apache service urgently. Now that the security threat is handled, you need to ensure that the threat is mitigated automatically in the future.

The best way to mitigate future threats is by using Ansible playbooks with the [`ansible-playbook`](https://docs.ansible.com/ansible/latest/user_guide/playbooks.html) command instead of ad-hoc commands.

1\. Create a project directory in your home directory and switch to that directory. You can name the directory as you prefer, but for this demo, the directory is called _~/ansible\_become\_playbook\_demo._

This directory will contain the [playbook](https://www.redhat.com/en/topics/automation/what-is-an-ansible-playbook#:~:text=An%20Ansible%C2%AE%20playbook%20is,make%20up%20an%20Ansible%20inventory) you’ll invoke later in the section.

```yaml
mkdir ~/ansible_become_playbook_demo
cd ~/ansible_become_playbook_demo
```

2\. Next, create a file called _my\_playbook.yml_ in the _~/ansible\_become\_playbook\_demo_ directory and paste in the following YAML playbook contents.

This playbook has a task that uses the [Ansible line-in-file module](https://docs.ansible.com/ansible/latest/collections/ansible/builtin/lineinfile_module.html) to check if `ADMIN` is present in the /etc/sudoers file; if not, the task adds it on the remote machine.

The Playbook also contains two parameters:

*   `become_method` – allows you to activate the privilege escalation,
*   `become_user` – allows switching to other users (`shankym`).

> _become\_method_ _overrides the default method set in ansible.cfg configuration file._

> _You can set the `become: yes` if you wish the currently logged-in user to run the task in the Ansible playbook._

```yaml
---
- name: Ansible become Playbook demo
# Defining the remote server where Ansible Playbook will be executed.
  hosts: web
# Set become_method to su to activate privilege escalation.
  become_method: su
# Switching to the new user shankym
  become_user: shankym
  tasks:

# Task to Check the Sudoers file if Admins are allowed to perform all operations 
    - name: Validate the sudoers file before saving
      ansible.builtin.lineinfile:
         path: /etc/sudoers
         state: present
         regexp: '^%ADMIN ALL='
         line: '%ADMIN ALL=(ALL) NOPASSWD: ALL'
```

3\. Run the below command to invoke the playbook (`my_playbook.yml`) you previously created (step two). The playbook then executes the tasks to add or update all the lines defined in the playbook on the remote host.

> _Validating the Ansible playbook using the [`--check`](https://docs.ansible.com/ansible/latest/user_guide/playbooks_checkmode.html#using-check-mode) flag with the `ansible-playbook` command shown below is a good practice before actually executing the playbook_.

```bash
ansible-playbook my_playbook.yml 
```

Below, you can see that the **TASK** has the OK status, which shows tasks don’t require any changes.

![Executing the Ansible Playbook](https://adamtheautomator.com/wp-content/uploads/2022/02/image-116.png)

Executing the Ansible Playbook

4\. Now, SSH into the remote host using your favorite SSH client.

5\. Finally, run the [`cat`](https://www.geeksforgeeks.org/cat-command-in-linux-with-examples/) command below to verify if the line defined in the _my\_playbook.yml_ are updated or added on the remote host. `# To verify if admin is present with full privileges, and if not, add it cat /etc/sudoers`

```bash
# To verify if admin is present with full privileges, and if not, add it
cat /etc/sudoers
```

The below screenshot confirms that the **admin** is already added in the _/etc/sudoers_ file.

![Verifying the /etc/sudoers file in the Remote Node](https://adamtheautomator.com/wp-content/uploads/2022/02/image-117.png)

Verifying the _/etc/sudoers_ file in the Remote Node

## Working with Ansible `become` with Connection Variables

You previously learned how to run the Ansible playbook for a remote node with a particular user variable within the Ansible playbook. But if you need to manage different remote nodes or groups of remote nodes with different users or rights, consider declaring the Ansible connection variables.

Create a file named _inventory_ in the same _~/ansible\_become\_playbook\_demo_ directory and populate the file with the following lines.

The below inventory contains the following:

*   The hostname of the remote nodes (`ip-10-111-11-149/150/151`).
*   The user that will run the task within the playbook (`ansible_user`).
*   If the user needs to be run all tasks as root (`ansible_become_method=su`).

> _You could use `ansible_become_password` if you need to define the password of the `ansible_user` parameter. Or use `ansible_common_remote_group` if you declared all the remote nodes within a group in the inventory._

```bash
# Declaring the hostname of the first remote node and the user 
# to execute the task is ubuntu
ip-10-111-11-149 ansible_user=ubuntu
# Declaring the hostname of the second remote node and the user 
# to execute the task is ubuntu1
ip-10-111-11-150 ansible_user=ubuntu1 ansible_become_method=su
# Declaring the hostname of the third remote node and the user 
# to execute the task is ubuntu2
ip-10-111-11-151 ansible_user=ubuntu2 ansible_become_method=su
```

Now open the same playbook (_my\_playbook.yml_), remove the `become_user` and `become_method` parameters, and replace `hosts: web` with `hosts: ip-10-111-11-149`.

The Ansible playbook below executes only on the `ip-10-111-11-149` host with ubuntu user and executes the task to validate the `/etc/sudoers` file.

```yaml
---
- name: Ansible become Playbook demo
# Defining the host server based on your inventory file
# where Ansible Playbook will be executed.
# ip-10-111-11-150 (ubuntu1) | ip-10-111-11-151 (ubuntu2)
	hosts: ip-10-111-11-149  # ubuntu
  tasks:
# Task to Check the Sudoers file if Admins can perform all operations
    - name: Validate the sudoers file before saving
# Executing the Ansible Lineinfile module in the Playbook
      ansible.builtin.lineinfile:
# Checking the sudoers file in etc directory
         path: /etc/sudoers
         state: present
         regexp: '^%ADMIN ALL='
         line: '%ADMIN ALL=(ALL) NOPASSWD: ALL'
```

![Executing the Ansible Playbook to validate the sudoers file using the ansible-playbook command](https://adamtheautomator.com/wp-content/uploads/2022/02/image-118.png)

Executing the Ansible Playbook to validate the sudoers file using the ansible-playbook command

## Conclusion

In this tutorial, you’ve taken advantage of the Ansible `become` parameter to manage services with a single command. You also learned how to use various Ansible `become` parameters to become another user while deploying or managing remote nodes.

Now that you have sound knowledge of the Ansible become, which method or parameter will you implement next in your Ansible playbook?

Share this article

[Share on X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fadamtheautomator.com%2Fansible-become%2F&text=How%20to%20Secure%20Ansible%20Playbooks%20with%20Ansible%20Become)[Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fadamtheautomator.com%2Fansible-become%2F)[Share on LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fadamtheautomator.com%2Fansible-become%2F)

## Related Posts

![](https://adamtheautomator.com/wp-content/uploads/2021/04/A-Step-by-Step-Guide-to-Getting-Started-with-Ansible-on-Windows.jpg)

### [Mastering Ansible on Windows: Your Go-To Expert Guide](/ansible-on-windows/)

Ansible on Windows made simple. A complete guide to hassle-free installation and configuration, perfect for users seeking quick and effective mastery.

![](https://adamtheautomator.com/wp-content/uploads/2022/10/How-to-Manage-Python-Libraries-with-Ansible-Pip.jpg)

### [How to Manage Python Libraries with Ansible Pip](/ansible-pip/)

Learn how to effectively manage Python libraries with the Ansible Pip module and take control of your Python dependencies!

![](https://adamtheautomator.com/wp-content/uploads/2022/06/Highly-Effective-Automation-with-Ansible-AWX.jpg)

### [Highly Effective Automation with Ansible AWX](/ansible-awx/)

Learn how Ansible AWX can take your Ansible playbooks to the next level and automate all the things with this ATA Learning tutorial!

## Categories

*   [IT Ops](/category/it-ops/)
*   [Cloud](/category/cloud/)
*   [DevOps](/category/devops/)
*   [Home Ops](/category/home-ops/)
*   [Information Security](/category/infosec/)
*   [Software Development](/category/software-development/)

## Site

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Copyright 2026© ATA Learning | [Privacy Policy](/privacy/)
