# Error: groupadd: Permission denied / Ansible become fails when Packer runs as root (Docker)

## TL;DR
Do not run Packer as root in Docker. Ansible's `become` breaks when the Packer process itself is root. Build a custom image with a non-root user and run Packer as that user.

## The error

```
amazon-ebs.golden-ami: fatal: [default]: FAILED! => {"changed": false, "msg": "groupadd: Permission denied.\ngroupadd: cannot lock /etc/group; try again later.\n", "name": "consul"}
```

## Fix it

1. Confirm Packer runs as root: `whoami` in your CI container (the `hashicorp/packer:light` image defaults to root).
   - Success check: you see `root`.
2. Build a custom image: install packer and ansible on a base like Ubuntu, create a non-root user, and `USER` that user.
   - Success check: `whoami` in the new image prints the non-root user.
3. Re-run the pipeline with the custom image.
   - Success check: `become: true` tasks execute as root on the *guest* correctly.
4. Keep the playbook's `become: true`/`become_user: root`; the problem was the Packer-side user, not the playbook.
   - Success check: no playbook changes needed.

## When to use this
You hit this running Packer in Docker (especially `hashicorp/packer:light`) with the Ansible provisioner and `become: true`.

## When NOT to use this
Do not use this for permission failures on the guest when Packer runs as non-root. Those are genuine guest permission issues.

## Compatibility
Packer 1.x, ansible provisioner, Docker-based CI (GitLab, GitHub Actions container jobs).

## Variants
- Other `Permission denied` failures on user/group/file tasks under the same setup
- The playbook working locally (non-root Packer) but failing in CI (root Packer)

## Root cause
When Packer itself runs as root, its Ansible wrapper mishandles privilege escalation: `become: yes` fails because the connection is already privileged in a way Ansible does not expect. The docs explicitly recommend against running Packer as root.

## Edge cases
- GitLab CI does not let you change the image user without hacks; the custom image with `USER` baked in is the clean fix.
- The Alpine-based `packer:light` image also lacks many tools; the Ubuntu-based custom image fixes that too.
