Removing install user with PackerWhat's the default superuser username/password for postgres after a new install?Ansible playbook not working trying to run make & configure with complex switchesAnsible Fails to Authenticate Sudo Even When Sudo Pass is GivenAnsible shell command fails under sudo when it should succeedAnsible not executing within Packer BuildIs there any way to provision bare-metal with Packer?What is reasonable performance for a simple Ansible playbook against ~100 hosts?Packer won't correctly use private key for SSH auth in provisioning stepManage list of local users via ansibleAnsible: check supplied tags are valid before running a playbook
Co-worker is now managing my team. Does this mean that I'm being demoted?
Is it possible for underground bunkers on different continents to be connected?
The title "Mord mit Aussicht" explained
Difference between "drift" and "wander"
Reflecting Telescope Blind Spot?
Should I worry about having my credit pulled multiple times while car shopping?
Will users know a CardView is clickable
How to address players struggling with simple controls?
Interview was just a one hour panel. Got an offer the next day; do I accept or is this a red flag?
How to test soql with For Update statement
How to make a villain when your PCs are villains?
Background for black and white chart
Digital signature that is only verifiable by one specific person
My parents claim they cannot pay for my college education; what are my options?
Is it possible to have battery technology that can't be duplicated?
Does PC weight have a mechanical effect?
Does WiFi affect the quality of images downloaded from the internet?
Does the use of English words weaken diceware passphrases
How can this shape perfectly cover a cube?
I sent an angry e-mail to my interviewers about a conflict at my home institution. Could this affect my application?
How to avoid offending original culture when making conculture inspired from original
Why can't we feel the Earth's revolution?
Do items with curse of vanishing disappear from shulker boxes?
How to remove multiple elements from Set/Map AND knowing which ones were removed?
Removing install user with Packer
What's the default superuser username/password for postgres after a new install?Ansible playbook not working trying to run make & configure with complex switchesAnsible Fails to Authenticate Sudo Even When Sudo Pass is GivenAnsible shell command fails under sudo when it should succeedAnsible not executing within Packer BuildIs there any way to provision bare-metal with Packer?What is reasonable performance for a simple Ansible playbook against ~100 hosts?Packer won't correctly use private key for SSH auth in provisioning stepManage list of local users via ansibleAnsible: check supplied tags are valid before running a playbook
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
When a VM is first created, it gets an install user that is used to run the provisioning. I want to remove this user at the last step because it's not necessarily secure and it's unnecessary. However, Packer runs all of the provisioners as this user. I've tried using Ansible, but it still seems to be using this user in some capacity and thus the Ansible playbook cannot actually remove it without failing (saying that there programs still running as the given user). Rather than bumble around, I'm asking if anyone has any ideas as to how to achieve this goal, which should be simple and has turned out not to be.
ansible user-management packer
add a comment |
When a VM is first created, it gets an install user that is used to run the provisioning. I want to remove this user at the last step because it's not necessarily secure and it's unnecessary. However, Packer runs all of the provisioners as this user. I've tried using Ansible, but it still seems to be using this user in some capacity and thus the Ansible playbook cannot actually remove it without failing (saying that there programs still running as the given user). Rather than bumble around, I'm asking if anyone has any ideas as to how to achieve this goal, which should be simple and has turned out not to be.
ansible user-management packer
add a comment |
When a VM is first created, it gets an install user that is used to run the provisioning. I want to remove this user at the last step because it's not necessarily secure and it's unnecessary. However, Packer runs all of the provisioners as this user. I've tried using Ansible, but it still seems to be using this user in some capacity and thus the Ansible playbook cannot actually remove it without failing (saying that there programs still running as the given user). Rather than bumble around, I'm asking if anyone has any ideas as to how to achieve this goal, which should be simple and has turned out not to be.
ansible user-management packer
When a VM is first created, it gets an install user that is used to run the provisioning. I want to remove this user at the last step because it's not necessarily secure and it's unnecessary. However, Packer runs all of the provisioners as this user. I've tried using Ansible, but it still seems to be using this user in some capacity and thus the Ansible playbook cannot actually remove it without failing (saying that there programs still running as the given user). Rather than bumble around, I'm asking if anyone has any ideas as to how to achieve this goal, which should be simple and has turned out not to be.
ansible user-management packer
ansible user-management packer
asked Apr 3 '17 at 18:29
siridesiride
276516
276516
add a comment |
add a comment |
2 Answers
2
active
oldest
votes
Schedule a cron job to remove the user with @reboot
option or add a few lines to rc scripts to do the same.
I wasn't able to get@reboot
to work, but having it run once a minute and then delete itself once it runs works well enough. A little irritating, but it works.
– siride
Apr 5 '17 at 14:36
add a comment |
I realize this is a rather old question, but I didn't like the idea of using a cronjob (or cloud-init, or anything that happens after the image would be instantiated) for this, and found what I find to be a better solution using packer itself. This works in Packer 1.4:
"type": "shell",
"skip_clean": true,
"execute_command": "chmod +x .Path ; sudo env .Vars .Path ; rm -f .Path ",
"inline": [
"rm -f /etc/sudoers.d/90-cloud-init-users",
"/usr/sbin/userdel -r -f fedora",
]
This assumes your install user is named fedora
— it leverages Packer's skip_clean
option to skip the deletion of the shell script after the inline
section completes (which, given that the fedora
user no longer exists, was guaranteed to fail).
Also note that if you have SSH agent forwarding turned on with packer, this may leave traces of the agent socket behind in the image.
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f842315%2fremoving-install-user-with-packer%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
2 Answers
2
active
oldest
votes
2 Answers
2
active
oldest
votes
active
oldest
votes
active
oldest
votes
Schedule a cron job to remove the user with @reboot
option or add a few lines to rc scripts to do the same.
I wasn't able to get@reboot
to work, but having it run once a minute and then delete itself once it runs works well enough. A little irritating, but it works.
– siride
Apr 5 '17 at 14:36
add a comment |
Schedule a cron job to remove the user with @reboot
option or add a few lines to rc scripts to do the same.
I wasn't able to get@reboot
to work, but having it run once a minute and then delete itself once it runs works well enough. A little irritating, but it works.
– siride
Apr 5 '17 at 14:36
add a comment |
Schedule a cron job to remove the user with @reboot
option or add a few lines to rc scripts to do the same.
Schedule a cron job to remove the user with @reboot
option or add a few lines to rc scripts to do the same.
answered Apr 4 '17 at 7:30
techraftechraf
3,38381737
3,38381737
I wasn't able to get@reboot
to work, but having it run once a minute and then delete itself once it runs works well enough. A little irritating, but it works.
– siride
Apr 5 '17 at 14:36
add a comment |
I wasn't able to get@reboot
to work, but having it run once a minute and then delete itself once it runs works well enough. A little irritating, but it works.
– siride
Apr 5 '17 at 14:36
I wasn't able to get
@reboot
to work, but having it run once a minute and then delete itself once it runs works well enough. A little irritating, but it works.– siride
Apr 5 '17 at 14:36
I wasn't able to get
@reboot
to work, but having it run once a minute and then delete itself once it runs works well enough. A little irritating, but it works.– siride
Apr 5 '17 at 14:36
add a comment |
I realize this is a rather old question, but I didn't like the idea of using a cronjob (or cloud-init, or anything that happens after the image would be instantiated) for this, and found what I find to be a better solution using packer itself. This works in Packer 1.4:
"type": "shell",
"skip_clean": true,
"execute_command": "chmod +x .Path ; sudo env .Vars .Path ; rm -f .Path ",
"inline": [
"rm -f /etc/sudoers.d/90-cloud-init-users",
"/usr/sbin/userdel -r -f fedora",
]
This assumes your install user is named fedora
— it leverages Packer's skip_clean
option to skip the deletion of the shell script after the inline
section completes (which, given that the fedora
user no longer exists, was guaranteed to fail).
Also note that if you have SSH agent forwarding turned on with packer, this may leave traces of the agent socket behind in the image.
add a comment |
I realize this is a rather old question, but I didn't like the idea of using a cronjob (or cloud-init, or anything that happens after the image would be instantiated) for this, and found what I find to be a better solution using packer itself. This works in Packer 1.4:
"type": "shell",
"skip_clean": true,
"execute_command": "chmod +x .Path ; sudo env .Vars .Path ; rm -f .Path ",
"inline": [
"rm -f /etc/sudoers.d/90-cloud-init-users",
"/usr/sbin/userdel -r -f fedora",
]
This assumes your install user is named fedora
— it leverages Packer's skip_clean
option to skip the deletion of the shell script after the inline
section completes (which, given that the fedora
user no longer exists, was guaranteed to fail).
Also note that if you have SSH agent forwarding turned on with packer, this may leave traces of the agent socket behind in the image.
add a comment |
I realize this is a rather old question, but I didn't like the idea of using a cronjob (or cloud-init, or anything that happens after the image would be instantiated) for this, and found what I find to be a better solution using packer itself. This works in Packer 1.4:
"type": "shell",
"skip_clean": true,
"execute_command": "chmod +x .Path ; sudo env .Vars .Path ; rm -f .Path ",
"inline": [
"rm -f /etc/sudoers.d/90-cloud-init-users",
"/usr/sbin/userdel -r -f fedora",
]
This assumes your install user is named fedora
— it leverages Packer's skip_clean
option to skip the deletion of the shell script after the inline
section completes (which, given that the fedora
user no longer exists, was guaranteed to fail).
Also note that if you have SSH agent forwarding turned on with packer, this may leave traces of the agent socket behind in the image.
I realize this is a rather old question, but I didn't like the idea of using a cronjob (or cloud-init, or anything that happens after the image would be instantiated) for this, and found what I find to be a better solution using packer itself. This works in Packer 1.4:
"type": "shell",
"skip_clean": true,
"execute_command": "chmod +x .Path ; sudo env .Vars .Path ; rm -f .Path ",
"inline": [
"rm -f /etc/sudoers.d/90-cloud-init-users",
"/usr/sbin/userdel -r -f fedora",
]
This assumes your install user is named fedora
— it leverages Packer's skip_clean
option to skip the deletion of the shell script after the inline
section completes (which, given that the fedora
user no longer exists, was guaranteed to fail).
Also note that if you have SSH agent forwarding turned on with packer, this may leave traces of the agent socket behind in the image.
edited May 30 at 18:42
answered May 30 at 15:55
Joey ColemanJoey Coleman
1013
1013
add a comment |
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f842315%2fremoving-install-user-with-packer%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown