Fix Ansible "Missing sudo Password" & Become Errors

The Error

fatal: [server]: FAILED! => {
    "msg": "Missing sudo password"
}

Solution 1: Pass sudo Password at Runtime

ansible-playbook playbook.yml --ask-become-pass
# Or shorter
ansible-playbook playbook.yml -K

Solution 2: Configure NOPASSWD in sudoers

On the remote host:

sudo visudo
# Add this line:
deploy ALL=(ALL) NOPASSWD: ALL

Or for specific commands only:

deploy ALL=(ALL) NOPASSWD: /usr/bin/apt-get, /usr/bin/systemctl

Solution 3: Store Password in Vault

# group_vars/all/vault.yml (encrypted with ansible-vault)
ansible_become_password: "{{ vault_sudo_password }}"
ansible-vault encrypt group_vars/all/vault.yml
ansible-playbook playbook.yml --ask-vault-pass

Solution 4: Set become in ansible.cfg

[privilege_escalation]
become = true
become_method = sudo
become_user = root
become_ask_pass = false

Solution 5: Per-Task Become

- name: This task needs root
  ansible.builtin.apt:
    name: nginx
    state: present
  become: true

- name: This task runs as regular user
  ansible.builtin.command: whoami
  # No become — runs as ansible_user

Common Mistakes

Wrong become_method

# For su instead of sudo
- hosts: servers
  become: true
  become_method: su
  become_user: root

become_user vs become

# become: true + become_user runs as that user
- name: Run as postgres
  ansible.builtin.command: psql -l
  become: true
  become_user: postgres

Timeout Waiting for Password Prompt

# ansible.cfg — increase timeout
[defaults]
timeout = 30

Debugging

# Test become directly
ansible server -m command -a "whoami" --become -K -vvv

Conclusion

Use --ask-become-pass for interactive use, NOPASSWD in sudoers for automation, and Ansible Vault for stored passwords. Always use become: true only on tasks that actually need root.