This commit is contained in:
2020-10-01 01:21:46 +02:00
parent 30faa849ac
commit 5aaee7646b
9 changed files with 297 additions and 34 deletions

View File

@ -1283,50 +1283,131 @@ samba_shares:
# ==========
# vars used by roles/common/tasks/sudoers.yml
# vars used by roles/common/tasks/sudoers-pc.yml
# ==========
sudo_users:
sudo_pc_users:
- chris
- sysadm
# /etc/sudoers
#
sudoers_defaults:
sudoers_pc_defaults:
- env_reset
- mail_badpass
- 'secure_path="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"'
sudoers_host_aliases: []
sudoers_pc_host_aliases: []
sudoers_user_aliases: []
sudoers_pc_user_aliases: []
sudoers_cmnd_aliases: []
sudoers_pc_cmnd_aliases: []
sudoers_runas_aliases: []
sudoers_pc_runas_aliases: []
sudoers_user_privileges:
sudoers_pc_user_privileges:
- name: root
entry: 'ALL=(ALL:ALL) ALL'
sudoers_group_privileges: []
sudoers_pc_group_privileges: []
# /etc/sudoers.d/50-user
#
sudoers_file_defaults: []
sudoers_pc_file_defaults: []
sudoers_file_host_aliases: []
sudoers_pc_file_host_aliases: []
sudoers_file_user_aliases: []
sudoers_pc_file_user_aliases: []
sudoers_file_cmnd_aliases:
sudoers_pc_file_cmnd_aliases:
- name: MOUNT
entry: '/bin/mount,/bin/umount'
sudoers_file_runas_aliases: []
sudoers_pc_file_runas_aliases: []
# ==========
# vars used by roles/common/tasks/sudoers-server.yml
# ==========
sudo_server_users:
- chris
- sysadm
# /etc/sudoers
#
sudoers_server_defaults:
- env_reset
- mail_badpass
- 'secure_path="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"'
sudoers_server_host_aliases: []
sudoers_server_user_aliases: []
sudoers_server_cmnd_aliases: []
sudoers_server_runas_aliases: []
sudoers_server_user_privileges:
- name: root
entry: 'ALL=(ALL:ALL) ALL'
sudoers_server_group_privileges: []
sudoers_server_remove_user:
- back
- www-data
# /etc/sudoers.d/50-user
#
sudoers_server_file_defaults: []
sudoers_server_file_host_aliases: []
sudoers_server_file_user_aliases: []
sudoers_server_file_cmnd_aliases: []
sudoers_server_file_runas_aliases: []
sudoers_server_file_user_back_privileges:
- 'ALL=(root) NOPASSWD: /usr/bin/rsync'
- 'ALL=(root) NOPASSWD: /usr/bin/find'
- 'ALL=(root) NOPASSWD: /usr/bin/realpath'
sudoers_server_file_user_back_disk_privileges:
- 'ALL=(root) NOPASSWD: /usr/bin/which'
- 'ALL=(root) NOPASSWD: /sbin/hdparm -I /dev/*'
- 'ALL=(root) NOPASSWD: /sbin/fdisk'
- 'ALL=(root) NOPASSWD: /sbin/sgdisk'
- 'ALL=(root) NOPASSWD: /sbin/sfdisk -d /dev/*'
- 'ALL=(root) NOPASSWD: /bin/dd if=/dev/*'
- 'ALL=(root) NOPASSWD: /sbin/parted'
- 'ALL=(root) NOPASSWD: /sbin/gdisk'
# sudoers_server_file_user_privileges
# - name: <name1>
# entry: <sudoer-entry1>
# - name : <name2>
# entry: <sudoer-entry22>
# - ...
#
sudoers_server_file_user_privileges: []
# sudoers_server_file_group_privileges
# - name: <name1>
# entry: <sudoer-entry1>
# - name : <name2>
# entry: <sudoer-entry22>
# - ...
#
sudoers_server_file_group_privileges: []