Skip to content

bug: Action fails on yum install due to sudo password requirement #31

Description

@salmankadaya

The setup-python-amazon-linux action fails during the dependency installation step. Specifically, the command sudo yum install -y tar gzip which prompts for a password, causing the process to hang and eventually fail with the error: sudo: a terminal is required to read the password.

To Reproduce
Steps to reproduce the behavior:

  1. Use kishaningithub/setup-python-amazon-linux@v1 in a workflow.
  2. Run the workflow on a self-hosted Amazon Linux runner.
  3. See error in the "Run sudo yum install..." step.

Error Log

Run sudo yum install -y tar gzip which
  sudo yum install -y tar gzip which
  shell: /usr/bin/bash --noprofile --norc -e -o pipefail {0}

We trust you have received the usual lecture from the local System
Administrator. It usually boils down to these three things:

    #1) Respect the privacy of others.
    #2) Think before you type.
    #3) With great power comes great responsibility.

For security reasons, the password you type will not be visible.

sudo: a terminal is required to read the password; either use the -S option to read from standard input or configure an askpass helper
sudo: a password is required
Error: Process completed with exit code 1.

Expected behavior:

The action should be able to install necessary dependencies (tar, gzip, which) without requiring interactive password entry, or provide a way to bypass this check if dependencies are already present.

Activity

  1. kishaningithub commented on May 6, 2026

    @kishaningithub
    Owner

    @salmankadaya What is the version of amazon linux you are using?

  2. kishaningithub commented on May 6, 2026

    @kishaningithub
    Owner

    Also can you check the user and check if the user is in the sudoers list?

  3. salmankadaya commented on May 7, 2026

    @salmankadaya
    Author

    Hello @kishaningithub, The OS version is Amazon Linux 2023.10.20260325.
    I would like to check whether the user has been added to the sudoers list.
    For your information, this self-hosted runner was created by the infrastructure team, and I do not have admin access to it.
    Could you please advise how a user can be added to the sudoers list and which user needs to be added?

  4. kishaningithub commented on May 8, 2026

    @kishaningithub
    Owner

    @salmankadaya Within a CI environment a sudo should never ask for a password. To verify this check if you have something like the following in /etc/sudoers or within a file under /etc/sudoers.d/

    ec2-user ALL=(ALL) NOPASSWD: ALL
    

    It is a best practice generally to add lines like the above in a separate file inside /etc/sudoers.d/ so that it is separate from the global /etc/sudoers

    Ask your infrastructure team to create a file /etc/sudoers.d/github-runner (The name can be anything) and put the above line (assuming your default user is ec2-user) then this action and anything else which requires a sudo mode should work as expected.

  5. kishaningithub commented on May 8, 2026

    @kishaningithub
    Owner

    Have created a new PR to require sudo only if the specified command (tar,gzip,which) is not already present in the environment #32

  6. kishaningithub commented on May 8, 2026

    @kishaningithub
    Owner
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions