Right now, all jobs that are kicked off using the "run" command
line tool are treated and logged as if they are executed by "admin"
(or more specifically, the value of framework.server.username).
This means that command line users have access to all jobs all
the time and their executions are not specifically logged as being
from them.
We need a mechanism that allows the unix user to be passed to
the rundeck server process so that:
- aclpolicy can limit the jobs that the unix user can
do.
- the user can be logged in the rundeck database as the executor
of the job.
This assumes a direct mapping between unix users and rundeck
users (for example if they authenticated from the same source); it
would be nice not to require a password in this case.
We should also have a way to pass any arbitrary
username/password for the same kind of purposes; this could be
configured locally per account (perhaps via environment variable);
see #247 for a related issue.