]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/sudo/files/sudoers
nagios needs to be able to run systemctl as root otherwise dbus is needed
[dsa-puppet.git] / modules / sudo / files / sudoers
index 780eb11bfb2fe8614d2a84e28119341ef89f1523..1407862221f477936ba7fc6f9d95ed942b6f5632 100644 (file)
@@ -50,6 +50,7 @@ root  ALL=(ALL) ALL
 %zivit-admins  ZIVITHOSTS=(ALL)        NOPASSWD: ALL
 
 # nagios
+nagios         ALL=(ALL)       NOPASSWD: /bin/systemctl is-system-running
 nagios         MQ_HOSTS=(rabbitmq)     NOPASSWD: /usr/sbin/rabbitmqctl list_queues -p dsa name messages consumers
 nagios         ALL=(ALL)       NOPASSWD: /usr/sbin/service ekeyd-egd-linux restart
 nagios         ALL=(ALL)       NOPASSWD: /usr/sbin/service samhain restart
@@ -75,7 +76,7 @@ nagios                AACRAIDHOSTS=(ALL)      NOPASSWD: /usr/local/bin/arcconf GETCONFIG 1 LD, /usr
 nagios         MEGARAIDHOSTS=(ALL)     NOPASSWD: /usr/local/bin/megarc -AllAdpInfo -nolog, /usr/local/bin/megarc -dispCfg -a0 -nolog
 nagios         MEGACTLHOSTS=(ALL)      NOPASSWD: /usr/sbin/megactl -Hv
 # other nagios things
-nagios         backuphost,storace=(debbackup)  NOPASSWD: /usr/lib/nagios/plugins/dsa-check-backuppg ""
+nagios         storace=(debbackup)     NOPASSWD: /usr/lib/nagios/plugins/dsa-check-backuppg ""
 
 # groups and their role accounts
 %auditor       ALL=(accounting)        ALL
@@ -207,7 +208,7 @@ debwww              WEBHOSTS=(archvsync)    NOPASSWD: /home/archvsync/webmirrors/runmirrors
 %list          LISTHOSTS=(amavis)              NOPASSWD: /usr/bin/sa-learn
 %list          LISTHOSTS=(amavis)              ALL
 # geodns may reload bind
-geodnssync     geo1,geo2,geo3=(root)   NOPASSWD: /etc/init.d/bind9 reload
+geodnssync     geo1,geo2,geo3=(root)   NOPASSWD: /usr/sbin/service bind9 reload
 geodnssync     geo1,geo2,geo3=(root)   NOPASSWD: /usr/sbin/rndc reconfig
 # pushed nagiosadm reload icinga on tchaikovsky
 nagiosadm      tchaikovsky=(root)              NOPASSWD: /usr/sbin/service icinga reload