docs: add note on become convention
Some checks failed
Ansible Lint Check / lint (push) Failing after 56s

This commit is contained in:
Iain Learmonth 2025-12-20 13:16:09 +00:00
parent cd7e824890
commit d188a70ff5

View file

@ -9,10 +9,18 @@ collections:
- src: git+https://guardianproject.dev/sr2/ansible-collection-core.git - src: git+https://guardianproject.dev/sr2/ansible-collection-core.git
version: "main" version: "main"
roles: roles:
- src: git+https://github.com/ansible-lockdown/RHEL9-CIS.git - src: git+https://guardianproject.dev/sr2/RHEL9-CIS.git
version: "2.0.3" version: "2.0.3-become"
``` ```
## Convention
We assume that these roles will be run initially as root, and then as an unprivileged user after initial bootstrap.
Some hardening may only be performed in the second run when we can see that the unprivileged user access is configured
and root access is no longer required.
If anything fails due to permissions when running as an unprivileged user, please report that in our
[issue tracker](https://guardianproject.dev/sr2/ansible-collection-core/issues).
## Licence ## Licence
Copyright © SR2 Communications Limited 2021-2025. Copyright © SR2 Communications Limited 2021-2025.