Yes, it is nasty. Because of that we are working on it: https://blueprints.launchpad.net/kolla-ansible/+spec/ansible-specific-task-become. In the near future, probably with the Ocata release, it will be possible to run the kolla-ansible Playbooks without escalating whole hosts.