+# on draghi, the domains git thing will run bind9 reload afterwards
+%dnsadm draghi,orff=(root) NOPASSWD: /etc/init.d/bind9 reload
+%dnsadm draghi,orff=(geodnssync) NOPASSWD: /usr/bin/make -C /srv/dns.debian.org/geo
+%adm draghi=(puppet) NOPASSWD: /usr/bin/make -s -C /srv/db.debian.org/var/gitnagios/dsa-nagios/config install
+# remote power to babylon5 in the same rack:
+joerg unger=(ALL) /usr/bin/sispmctl -t [12], /usr/bin/sispmctl -g [12]
+# wbadm can update all buildd* users' keys on buildd.d.o
+%wbadm grieg=(root) /usr/local/bin/update-buildd-sshkeys
+wbadm grieg=(postgres) NOPASSWD: /usr/bin/pg_dumpall --cluster 8.4/wanna-build
+# mirror push
+dak FTPHOSTS,SECHOSTS=(archvsync) NOPASSWD:/home/archvsync/runmirrors
+planet senfl=(archvsync) NOPASSWD: /home/archvsync/bin/runplanet ""
+# archvsync triggers snapshot
+archvsync sibelius,stabile=(snapshot) NOPASSWD: /srv/snapshot.debian.org/bin/update-trigger
+archvsync sibelius,stabile=(snapshot) NOPASSWD: /srv/2ndsnapshot/bin/update-trigger
+# allow the debbugs-mirror user on rietz to release the afs volume so changes make it to the read-only replicas
+debbugs-mirror rietz=(root) NOPASSWD: /usr/bin/vos release -id srv.mirrors.bugs -localauth
+# dak stuff
+%debian-release FTPHOSTS=(dak) /usr/local/bin/dak transitions --import *
+%ftpteam FTPHOSTS=(dak) /usr/local/bin/dak transitions --import *
+# security
+%security SECHOSTS=(dak) NOPASSWD: /usr/local/bin/dak new-security-install -[AR]
+%sec_public SECHOSTS=(dak) NOPASSWD: /usr/local/bin/dak new-security-install -[AR]
+%sec_public SECHOSTS=(dak) NOPASSWD: /home/dak/trigger_mirror
+dak SECHOSTS=(archvsync) NOPASSWD: /home/archvsync/signal_security
+# web stuff
+debwww WEBHOSTS=(archvsync) NOPASSWD: /home/archvsync/webmirrors/runmirrors
+%press WEBHOSTS=(debwww) /org/www.debian.org/update-part News
+# more list stuff
+%list LISTHOSTS=(root) /usr/sbin/postfix reload
+%list LISTHOSTS=(root) /usr/sbin/qshape, /usr/sbin/postsuper
+%list LISTHOSTS=(root) /etc/init.d/spamassassin, /etc/init.d/amavis
+%list LISTHOSTS=(amavis) NOPASSWD: /usr/bin/sa-learn
+%list LISTHOSTS=(amavis) ALL
+# geodns may reload bind
+geodnssync geo1,geo2,geo3=(root) NOPASSWD: /etc/init.d/bind9 reload
+geodnssync geo1,geo2,geo3=(root) NOPASSWD: /usr/sbin/rndc reconfig
+# fossology
+%fossy vivaldi=(root) /etc/init.d/fossology
+%fossy vivaldi=(fossy) ALL
+
+# Porter work
+%porter-alpha albeniz=(root) NOPASSWD: /usr/sbin/upgrade-porter-chroots, /usr/bin/apt-in-chroot
+%porter-armel abel,agricola=(root) NOPASSWD: /usr/sbin/upgrade-porter-chroots, /usr/bin/apt-in-chroot
+%porter-armel harris=(root) NOPASSWD: /usr/sbin/upgrade-porter-chroots, /usr/bin/apt-in-chroot
+%porter-amd64 pergolesi=(root) NOPASSWD: /usr/sbin/upgrade-porter-chroots, /usr/bin/apt-in-chroot
+%porter-hppa paer=(root) NOPASSWD: /usr/sbin/upgrade-porter-chroots, /usr/bin/apt-in-chroot
+%porter-ia64 merulo=(root) NOPASSWD: /usr/sbin/upgrade-porter-chroots, /usr/bin/apt-in-chroot
+%porter-mips eder,gabrielli=(root) NOPASSWD: /usr/sbin/upgrade-porter-chroots, /usr/bin/apt-in-chroot
+%porter-s390 zelenka=(root) NOPASSWD: /usr/sbin/upgrade-porter-chroots, /usr/bin/apt-in-chroot
+%porter-sparc smetana,sperger,zee=(root) NOPASSWD: /usr/sbin/upgrade-porter-chroots, /usr/bin/apt-in-chroot