diff --git a/docker/kolla-toolbox/ansible_sudoers b/docker/kolla-toolbox/ansible_sudoers index c43917f651..5a3f109b45 100644 --- a/docker/kolla-toolbox/ansible_sudoers +++ b/docker/kolla-toolbox/ansible_sudoers @@ -1 +1,3 @@ +Defaults secure_path="/opt/ansible/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" + ansible ALL=(root) NOPASSWD: /opt/ansible/bin/ansible localhost -m find_disks -a *, /usr/local/bin/ansible localhost -m find_disks -a * diff --git a/releasenotes/notes/swift-sudo-issue-84d37919c980a373.yaml b/releasenotes/notes/swift-sudo-issue-84d37919c980a373.yaml new file mode 100644 index 0000000000..5823848f74 --- /dev/null +++ b/releasenotes/notes/swift-sudo-issue-84d37919c980a373.yaml @@ -0,0 +1,7 @@ +--- +fixes: + - | + Fixes an issue with Swift deployment via Kolla Ansible caused by + the fix to CVE-2022-38060. + The kolla-toolbox container now have its own sudoers secure_path + configuration which allows the necessary binaries to execute.