X-Git-Url: https://git.donarmstrong.com/?a=blobdiff_plain;f=modules%2Fsudo%2Ffiles%2Fsudoers;h=e99dc6cce3408962c435775bb5a34eb7e868ad12;hb=ee6c1be33c3361ff9939dc02987ab10cd1fab924;hp=ebeefa73d431390941bfb8593770f00c891b4a1a;hpb=7bcc7a02bea538a591bd85d4e68819dba5d0467c;p=dsa-puppet.git diff --git a/modules/sudo/files/sudoers b/modules/sudo/files/sudoers index ebeefa73..e99dc6cc 100644 --- a/modules/sudo/files/sudoers +++ b/modules/sudo/files/sudoers @@ -27,7 +27,7 @@ Host_Alias WEBHOSTS = wolkenstein Host_Alias SECHOSTS = chopin Host_Alias FTPHOSTS = franck Host_Alias ZIVITHOSTS = zelenka, zandonai -Host_Alias AACRAIDHOSTS = paganini, respighi, beethoven, pettersson +Host_Alias AACRAIDHOSTS = respighi, beethoven, pettersson Host_Alias MEGARAIDHOSTS = rautavaara, sibelius Host_Alias MPTRAIDHOSTS = barber, biber, cilea, vitry, orff Host_Alias MEGACTLHOSTS = nielsen @@ -50,8 +50,9 @@ root ALL=(ALL) ALL %zivit-admins ZIVITHOSTS=(ALL) NOPASSWD: ALL # nagios -nagios MQ_HOSTS=(rabbitmq) NOPASSWD: /usr/sbin/rabbitmqctl list_queues -nagios ALL=(ALL) NOPASSWD: /etc/init.d/ekeyd-egd-linux restart +nagios MQ_HOSTS=(rabbitmq) NOPASSWD: /usr/sbin/rabbitmqctl list_queues -p dsa name messages consumers +nagios ALL=(ALL) NOPASSWD: /usr/sbin/service ekeyd-egd-linux restart +nagios ALL=(ALL) NOPASSWD: /usr/sbin/service samhain restart nagios ALL=(ALL) NOPASSWD: /usr/lib/nagios/plugins/dsa-check-dabackup "" nagios ALL=(ALL) NOPASSWD: /usr/lib/nagios/plugins/dsa-check-filesystems "" # with smartarray controllers @@ -118,6 +119,7 @@ nagios beethoven,backuphost=(debbackup) NOPASSWD: /usr/lib/nagios/plugins/dsa-c %secretary ALL=(secretary) ALL %sectracker ALL=(sectracker) ALL %security SECHOSTS=(mail_security) ALL +%security ALL=(security) ALL %snapshot ALL=(snapshot) ALL %uddadm ALL=(udd) ALL %volatile ALL=(volatile) ALL @@ -127,6 +129,7 @@ nagios beethoven,backuphost=(debbackup) NOPASSWD: /usr/lib/nagios/plugins/dsa-c %qa-core ALL=(qa) ALL %gobby gombert=(gobby) ALL %dacshelper diabelli=(www-data) ALL +%debsso diabelli=(debsso) ALL # the dak user gets to run stuff as dak-unpriv (for things like lintian checks) %ftptrainee FTPHOSTS=(dak-unpriv) NOPASSWD: /usr/bin/lintian @@ -153,8 +156,9 @@ debwww wolkenstein=(staticsync) NOPASSWD: /usr/local/bin/static-update-componen %blends dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component blends.debian.org %Debian dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component wnpp-by-tags.debian.net %Debian dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component mozilla.debian.net -%ports dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component ports.debian.org +%ports dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component www.ports.debian.org %debvoip dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component rtc.debian.org +%security dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component security-team.debian.org # The piuparts slave needs to handle chroots piupartss PIUPARTS_SLAVE_HOSTS=(ALL) NOPASSWD: ALL