From 8ba8e3d7ecc8fb4a72a2290f854c225251ace33c Mon Sep 17 00:00:00 2001 From: Antigravity Agent Date: Sat, 3 Oct 2026 00:17:41 -0400 Subject: [PATCH] NetVM: sudoers file sorts last (zz-) so NOPASSWD beats blanket grants --- bin/netvm-provision-edge.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/bin/netvm-provision-edge.sh b/bin/netvm-provision-edge.sh index a192439..2c741d4 100755 --- a/bin/netvm-provision-edge.sh +++ b/bin/netvm-provision-edge.sh @@ -7,7 +7,7 @@ set -euo pipefail OPERATOR_USER="${OPERATOR_USER:-$(whoami)}" REPO="$HOME/Projects/NetVM" -SUDOERS_FILE="/etc/sudoers.d/netvm-operator" +SUDOERS_FILE="/etc/sudoers.d/zz-netvm-operator" echo "== NetVM edge provisioning (operator user: $OPERATOR_USER) ==" @@ -29,7 +29,7 @@ fi # 3. sudoers allowlist: exact lifecycle scripts only, never blanket root sudo tee "$SUDOERS_FILE" > /dev/null << SUDOERS -# NetVM operator lifecycle access — managed by netvm-provision-edge.sh. +# NetVM operator lifecycle access — managed by netvm-provision-edge.sh. Named zz- so it sorts last: in sudoers the LAST matching entry wins, and this must beat any blanket (ALL) grant. # Lets the operator user bring node egress up/down and read topology. # WireGuard configs in /etc/netvm stay root-only; these scripts never print them. $OPERATOR_USER ALL=(root) NOPASSWD: $REPO/bin/netvm-node-up.sh *, $REPO/bin/netvm-node-down.sh *, $REPO/bin/netvm-topology.sh