Allowing a user to use systemctl with specific daemons, so ```systemctl * unit-name```, without a password. But anything outside of that I need a password.
Allowing a user to use systemctl with specific daemons, so ```systemctl * unit-name```, without a password. But anything outside of that I need a password.
It's more so the curious dev don't just go sudo bash and changes stuff willy nilly then forgets what they changed.
We do avoid wildcards like plague but honestly regexp support would be more useful, then our devs could just have say
^/bin/systemctl (start|stop|restart|status) app-([a-z0-9\.\-]+)$
and be pretty safe.To me this sounds like a feature for a non-default "root-manager", while the default should be kept simpler to avoid people falling into such traps.
But the point being that the users who have that also can just sudo anything anyways, and if an attacker is running shell commands, you're already in trouble.
I'm wondering if you're not right at this point though.