Dotfiles/setup/modules/FreeipaAnsible/ansible/ansipa-git-pull-sudoers

8 lines
422 B
Plaintext

# Managed by deploy-ansipa-git-pull.yml — do not edit by hand.
#
# Scoped to one exact command, no arguments, no argument substitution: a
# compromised _ansipa account can invoke the enforcer (which only does what
# the last GPG-signature-verified, fast-forward commit told it to) and
# nothing else — it cannot pivot to arbitrary root execution.
_ansipa ALL=(root) NOPASSWD: /usr/local/bin/ansipa-enforce-policies.sh