8 lines
422 B
Plaintext
8 lines
422 B
Plaintext
# Managed by deploy-ansipa-git-pull.yml — do not edit by hand.
|
|
#
|
|
# Scoped to one exact command, no arguments, no argument substitution: a
|
|
# compromised _ansipa account can invoke the enforcer (which only does what
|
|
# the last GPG-signature-verified, fast-forward commit told it to) and
|
|
# nothing else — it cannot pivot to arbitrary root execution.
|
|
_ansipa ALL=(root) NOPASSWD: /usr/local/bin/ansipa-enforce-policies.sh
|