NetVM: sudoers file sorts last (zz-) so NOPASSWD beats blanket grants
This commit is contained in:
@@ -7,7 +7,7 @@ set -euo pipefail
|
|||||||
|
|
||||||
OPERATOR_USER="${OPERATOR_USER:-$(whoami)}"
|
OPERATOR_USER="${OPERATOR_USER:-$(whoami)}"
|
||||||
REPO="$HOME/Projects/NetVM"
|
REPO="$HOME/Projects/NetVM"
|
||||||
SUDOERS_FILE="/etc/sudoers.d/netvm-operator"
|
SUDOERS_FILE="/etc/sudoers.d/zz-netvm-operator"
|
||||||
|
|
||||||
echo "== NetVM edge provisioning (operator user: $OPERATOR_USER) =="
|
echo "== NetVM edge provisioning (operator user: $OPERATOR_USER) =="
|
||||||
|
|
||||||
@@ -29,7 +29,7 @@ fi
|
|||||||
|
|
||||||
# 3. sudoers allowlist: exact lifecycle scripts only, never blanket root
|
# 3. sudoers allowlist: exact lifecycle scripts only, never blanket root
|
||||||
sudo tee "$SUDOERS_FILE" > /dev/null << SUDOERS
|
sudo tee "$SUDOERS_FILE" > /dev/null << SUDOERS
|
||||||
# NetVM operator lifecycle access — managed by netvm-provision-edge.sh.
|
# NetVM operator lifecycle access — managed by netvm-provision-edge.sh. Named zz- so it sorts last: in sudoers the LAST matching entry wins, and this must beat any blanket (ALL) grant.
|
||||||
# Lets the operator user bring node egress up/down and read topology.
|
# Lets the operator user bring node egress up/down and read topology.
|
||||||
# WireGuard configs in /etc/netvm stay root-only; these scripts never print them.
|
# WireGuard configs in /etc/netvm stay root-only; these scripts never print them.
|
||||||
$OPERATOR_USER ALL=(root) NOPASSWD: $REPO/bin/netvm-node-up.sh *, $REPO/bin/netvm-node-down.sh *, $REPO/bin/netvm-topology.sh
|
$OPERATOR_USER ALL=(root) NOPASSWD: $REPO/bin/netvm-node-up.sh *, $REPO/bin/netvm-node-down.sh *, $REPO/bin/netvm-topology.sh
|
||||||
|
|||||||
Reference in New Issue
Block a user