diff --git a/deploy.sh b/deploy.sh index a02aef6..85e9da1 100755 --- a/deploy.sh +++ b/deploy.sh @@ -426,11 +426,19 @@ fi # Prime sudo early if filesystem setup will need it, so the password prompt # happens HERE (visible, at the start) instead of blocking mid-provision. +# `sudo -v` alone ALWAYS attempts interactive validation -- it does not +# consult NOPASSWD -- so it fails without a TTY (cloud-init, ansible without +# a pty, unattended CI). Try `-n -v` first: on a NOPASSWD user it succeeds +# silently; otherwise we fall through to the interactive prompt for humans. _dr_probe="$(get_env OBMP_DATA_ROOT)"; _dr_probe="${_dr_probe:-/var/openbmp}" if [ ! -w "$(dirname "$_dr_probe")" ] || { [ -d "$_dr_probe" ] && [ ! -w "$_dr_probe" ]; }; then if [ "$(id -u)" -ne 0 ]; then - log "Filesystem setup under $_dr_probe needs sudo - authenticating now." - sudo -v || die "sudo authentication failed" + if sudo -n -v 2>/dev/null; then + log "Filesystem setup under $_dr_probe needs sudo - passwordless sudo OK." + else + log "Filesystem setup under $_dr_probe needs sudo - authenticating now." + sudo -v || die "sudo authentication failed" + fi fi fi