Dotfiles/docs/md
Amir Alexander Abdelbaki 87b62f368b feat(ansipa): rework binary blocking as per-user policy; add local_sudo device policy
policy-block-binary-<name> is now a FreeIPA *user* group instead of a host group,
so restrictions follow the user to every enrolled machine. The PATH wrapper is
installed on all hosts and checks group membership at runtime via id(1)/SSSD,
passing non-members through transparently. __ in the group name decodes to .
so Flatpak app IDs are supported (flatpak run fallback included). AppArmor layer
removed since per-user confinement requires a different approach and the wrapper
alone is sufficient. Adds local_sudo_<username> host group policy which writes
a sudoers drop-in granting that user full sudo on the specific device, reverted
on group leave.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-20 16:31:43 +02:00
..
archiso.md docs: update readme and docs for recent changes 2026-05-20 15:39:38 +02:00
editors.md docs: add full documentation site with CyberQueer HTML theme 2026-05-18 15:47:09 +02:00
freeipa-ansible.md feat(ansipa): rework binary blocking as per-user policy; add local_sudo device policy 2026-05-20 16:31:43 +02:00
hyprland.md docs: add full documentation site with CyberQueer HTML theme 2026-05-18 15:47:09 +02:00
index.md docs: add full documentation site with CyberQueer HTML theme 2026-05-18 15:47:09 +02:00
installation.md docs: add full documentation site with CyberQueer HTML theme 2026-05-18 15:47:09 +02:00
modules.md docs: add graphic design, video editing, and audio modules to modules reference 2026-05-20 15:48:46 +02:00
theming.md docs: add full documentation site with CyberQueer HTML theme 2026-05-18 15:47:09 +02:00
utilities.md docs: add full documentation site with CyberQueer HTML theme 2026-05-18 15:47:09 +02:00