Error: Ansible become fails with Permission denied when Packer runs as root (Docker)
Fixes Ansible provisioner failing with permission denied when Packer runs as root in Docker. For engineers running packer in CI containers whose become: true playbooks fail, the fix is not running Packer as root.
Error: groupadd: Permission denied / Ansible become fails when Packer runs as root (Docker)
TL;DR
Do not run Packer as root in Docker. Ansible's become breaks when the Packer process itself is root. Build a custom image with a non-root user and run Packer as that user.
The error
amazon-ebs.golden-ami: fatal: [default]: FAILED! => {"changed": false, "msg": "groupadd: Permission denied.\ngroupadd: cannot lock /etc/group; try again later.\n", "name": "consul"}Fix it
- Confirm Packer runs as root:
whoamiin your CI container (thehashicorp/packer:lightimage defaults to root).
- Success check: you see
root.
- Build a custom image: install packer and ansible on a base like Ubuntu, create a non-root user, and
USERthat user.
- Success check:
whoamiin the new image prints the non-root user.
- Re-run the pipeline with the custom image.
- Success check:
become: truetasks execute as root on the guest correctly.
- Keep the playbook's
become: true/become_user: root; the problem was the Packer-side user, not the playbook.
- Success check: no playbook changes needed.
When to use this
You hit this running Packer in Docker (especially hashicorp/packer:light) with the Ansible provisioner and become: true.
When NOT to use this
Do not use this for permission failures on the guest when Packer runs as non-root. Those are genuine guest permission issues.
Compatibility
Packer 1.x, ansible provisioner, Docker-based CI (GitLab, GitHub Actions container jobs).
Variants
- Other
Permission deniedfailures on user/group/file tasks under the same setup - The playbook working locally (non-root Packer) but failing in CI (root Packer)
Root cause
When Packer itself runs as root, its Ansible wrapper mishandles privilege escalation: become: yes fails because the connection is already privileged in a way Ansible does not expect. The docs explicitly recommend against running Packer as root.
Edge cases
- GitLab CI does not let you change the image user without hacks; the custom image with
USERbaked in is the clean fix. - The Alpine-based
packer:lightimage also lacks many tools; the Ubuntu-based custom image fixes that too.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.