diff --git a/jperm/ansible_api.py b/jperm/ansible_api.py index a71d36a63..20725908c 100644 --- a/jperm/ansible_api.py +++ b/jperm/ansible_api.py @@ -125,7 +125,7 @@ class MyRunner(MyInventory): self.results_raw = {} def run(self, module_name='shell', module_args='', timeout=10, forks=10, pattern='*', - become=False, become_method='sudo', become_user='root', become_pass=''): + become=False, become_method='sudo', become_user='root', become_pass='', transport='paramiko'): """ run module from andible ad-hoc. module_name: ansible module_name @@ -140,7 +140,8 @@ class MyRunner(MyInventory): become=become, become_method=become_method, become_user=become_user, - become_pass=become_pass + become_pass=become_pass, + transport=transport ) self.results_raw = hoc.run() logger.debug(self.results_raw) diff --git a/templates/jperm/role_sudo.j2 b/templates/jperm/role_sudo.j2 index a37276771..27ce08ea6 100644 --- a/templates/jperm/role_sudo.j2 +++ b/templates/jperm/role_sudo.j2 @@ -4,6 +4,13 @@ real_file=/etc/sudoers tmp_file=$(mktemp /tmp/XXXXXXX) +# fixed sudoers file path in bsd +isbsd=$(uname -a | grep -i 'freebsd' &> /dev/null && echo "yes" || echo "no") +if [ $isbsd == "yes" ]; then + real_file=/usr/local/etc/sudoers +fi + + # Backup sudoers file cp ${real_file} ${tmp_file} @@ -13,7 +20,11 @@ add_cmd_alias() { {% for sudo_name, sudo_cmd in sudo_alias.items %} {% if sudo_name != 'ALL' %} if $(grep '^Cmnd_Alias \<{{ sudo_name }}\>' ${sudo_file} &> /dev/null); then - sed -i 's@^Cmnd_Alias \<{{ sudo_name }}\>.*@Cmnd_Alias {{ sudo_name }} = {{ sudo_cmd }}@g' ${sudo_file} + if [ $isbsd == "yes" ]; then + sed -i .bk 's@^Cmnd_Alias \<{{ sudo_name }}\>.*@Cmnd_Alias {{ sudo_name }} = {{ sudo_cmd }}@g' ${sudo_file} + else + sed -i 's@^Cmnd_Alias \<{{ sudo_name }}\>.*@Cmnd_Alias {{ sudo_name }} = {{ sudo_cmd }}@g' ${sudo_file} + fi else echo "Cmnd_Alias {{ sudo_name }} = {{ sudo_cmd }}" >> ${sudo_file} fi @@ -27,7 +38,11 @@ add_role_chosen() { sudo_file=$1 {% for user, alias in sudo_user.items %} if $(grep '^{{ user }}\>' ${sudo_file} &> /dev/null); then - sed -i 's@^{{ user }}\>.*@{{ user }} ALL = (root) NOPASSWD: {{ alias }}@g' ${sudo_file} + if [ $isbsd == "yes" ]; then + sed -i .bk 's@^{{ user }}\>.*@{{ user }} ALL = (root) NOPASSWD: {{ alias }}@g' ${sudo_file} + else + sed -i 's@^{{ user }}\>.*@{{ user }} ALL = (root) NOPASSWD: {{ alias }}@g' ${sudo_file} + fi else echo "{{ user }} ALL = (root) NOPASSWD: {{ alias }}" >> ${sudo_file} fi