"sudo: No TTY Present and No Askpass Program Specified"

sudo needs a password but has no terminal to ask on — cron, CI, and scripts. The right fix is scoped NOPASSWD rules, never passwordless sudo everywhere.

What you'll see

Root causes

Non-interactive context asking for a password

cron/CI/docker exec have no TTY, so sudo can't prompt. If the user has no NOPASSWD rule, it aborts. Who it's running as determines the fix.

Missing or unset SUDO_ASKPASS

If you genuinely need sudo in a script, an askpass helper can supply the password — but NOPASSWD scoping is nearly always the better design.

Fix it

  1. Prefer: scope NOPASSWD to the specific commands the script needs
    echo '<user> ALL=(root) NOPASSWD: /usr/bin/systemctl restart myapp, /usr/bin/docker' | sudo EDITOR='tee' visudo -f /etc/sudoers.d/<user>-script
  2. Cron: use root's crontab instead of sudo-in-cron
    sudo crontab -e   # runs AS root: no sudo needed inside the job
  3. CI: give the runner user the one rule it needs
    # e.g. gitlab-runner: one NOPASSWD line for the deploy script — audit what it can run
  4. If you must pipe a password: askpass (last resort, credential handling risk)
    export SUDO_ASKPASS=/path/to/helper.sh ; sudo -A <cmd>   # helper must echo the password — avoid on shared hosts

Field note

NOPASSWD: ALL is the mistake — scope it to exact binary paths so your deploy script can't become root's shell. systemd timers with User=root are a cleaner alternative to sudo-in-cron entirely.

Common questions

Why not just add NOPASSWD: ALL for my CI user?

That grants the runner (and anything that can write its scripts) unrestricted root. Scope NOPASSWD to the specific binaries the pipeline needs — a compromise turns into 'can restart one service' instead of 'owns the box'.

What's the cleanest cron pattern?

Install the job in root's own crontab (sudo crontab -e) and drop sudo entirely, or use a systemd timer with the right User=/Group=. Fewer privilege boundaries crossed at runtime.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.