diff --git a/files/common/etc/logrotate.d/sudo-log b/files/common/etc/logrotate.d/sudo-log new file mode 100644 index 00000000..9d3e6a50 --- /dev/null +++ b/files/common/etc/logrotate.d/sudo-log @@ -0,0 +1,7 @@ +/var/log/sudo.log { + weekly + rotate 4 + compress + missingok + notifempty +} \ No newline at end of file diff --git a/files/common/etc/sudoers.d/delphix b/files/common/etc/sudoers.d/delphix index a350907f..3cdea8bf 100644 --- a/files/common/etc/sudoers.d/delphix +++ b/files/common/etc/sudoers.d/delphix @@ -15,3 +15,5 @@ # delphix ALL=(ALL) NOPASSWD:ALL +Defaults use_pty +Defaults logfile='/var/log/sudo.log' diff --git a/files/common/var/lib/delphix-platform/ansible/10-delphix-platform/roles/delphix-platform/tasks/main.yml b/files/common/var/lib/delphix-platform/ansible/10-delphix-platform/roles/delphix-platform/tasks/main.yml index e2002428..36f1956a 100644 --- a/files/common/var/lib/delphix-platform/ansible/10-delphix-platform/roles/delphix-platform/tasks/main.yml +++ b/files/common/var/lib/delphix-platform/ansible/10-delphix-platform/roles/delphix-platform/tasks/main.yml @@ -738,37 +738,3 @@ path: /etc/environment state: absent regexp: '^\s*PATH\s*=' - - -# -# Ensure Defaults use_pty is set in /etc/sudoers -# -- lineinfile: - path: /etc/sudoers - state: present - regexp: '^Defaults use_pty' - line: 'Defaults use_pty' - -# -# Ensure Defaults logfile is set in /etc/sudoers -# -- lineinfile: - path: /etc/sudoers - state: present - regexp: '^Defaults logfile=/var/log/sudo.log' - line: 'Defaults logfile=/var/log/sudo.log' - -# -# Create logrotate configuration for sudo.log -# -- copy: - dest: /etc/logrotate.d/sudo-log - content: | - /var/log/sudo.log { - weekly - rotate 4 - compress - missingok - notifempty - } - mode: '0644'