Error: sudo: sorry, you must have a tty to run sudo (Packer)
Fixes Packer provisioners failing on sudo with 'you must have a tty'. For engineers whose shell provisioner dies on sudo commands, the fix is allocating a pseudo-TTY.
Error: sudo: sorry, you must have a tty to run sudo (Packer provisioner)
TL;DR
The remote sudo requires a TTY and Packer's SSH session does not allocate one. Set ssh_pty to true in the builder configuration.
The error
sudo: sorry, you must have a tty to run sudo(often surfacing as Build 'amazon-ebs' errored: Error installing Chef: Install script exited with non-zero exit status 1 or a shell provisioner failure)
Fix it
Add
"ssh_pty": trueto the builder block (JSON) orssh_pty = true(HCL).- Success check: the setting is present in the builder, not the provisioner.
Re-run
packer build.- Success check: sudo commands in provisioners execute instead of failing.
If you control the image, the alternative is removing
requirettyfrom sudoers, butssh_ptyis the portable fix.- Success check: either path eliminates the error.
When to use this
You hit this when provisioner scripts calling sudo fail on AMIs whose sudoers has requiretty (notably Amazon Linux and RHEL-family images).
When NOT to use this
Do not use this for password prompts from sudo (sudo: no tty present is different; provide ssh_password or NOPASSWD) or for non-sudo script failures.
Compatibility
Packer 1.x, SSH communicator, sudo with requiretty.
Variants
Error installing Chef: Install script exited with non-zero exit status 1with the tty message buried in the log- Shell provisioner scripts failing only on their
sudolines
Root cause
Some distributions ship sudoers with Defaults requiretty. Packer's SSH sessions run without a pseudo-terminal by default, so sudo refuses to run at all.
Edge cases
ssh_ptycan change output buffering slightly; if a script parses interactive output, test it.- WinRM/Windows builders do not use this setting; it is SSH-only.