Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
[mirror/dsa-puppet.git] / modules / sudo / files / common / sudoers
index eb6b7d8..ff19ed5 100644 (file)
@@ -22,6 +22,7 @@ Defaults      env_reset
 # Host alias specification
 Host_Alias     QAHOSTS         = master, merkel
 Host_Alias     WEBHOSTS        = klecker, wolkenstein
+Host_Alias     SECHOSTS        = klecker, chopin
 # User alias specification
 User_Alias     QACORE          = aba, djpig, geissert, hertzog, jeroen, joerg, lucas, luk, myon, tbm, weasel, zack
 
@@ -41,6 +42,7 @@ admin         agnesi=(ALL)    ALL
 # nagios
 nagios         ALL=(ALL)       NOPASSWD: /usr/lib/nagios/plugins/dsa-check-dabackup ""
 # with smartarray controllers
+nagios         ALL=(ALL)       NOPASSWD: /sbin/hpasmcli ""
 nagios         ALL=(ALL)       NOPASSWD: /usr/bin/arrayprobe ""
 nagios         ALL=(ALL)       NOPASSWD: /usr/sbin/hpacucli controller all show
 nagios         ALL=(ALL)       NOPASSWD: /usr/sbin/hpacucli controller slot=[02] pd all show
@@ -103,6 +105,7 @@ joerg               unger=(ALL)             /usr/bin/sispmctl -t 1, /usr/bin/sispmctl -g 1
 # wbadm can update all buildd* users' keys on buildd.d.o
 %wbadm         raff=(root)             /usr/local/bin/update-buildd-sshkeys
 %wbadm         cimarosa=(root)         /usr/local/bin/update-buildd-sshkeys
+wbadm          cimarosa=(postgres)     NOPASSWD: /usr/bin/pg_dumpall --cluster 8.4/wanna-build
 # mirror push
 dak            ries=(archvsync)        NOPASSWD:/home/archvsync/runmirrors
 planet         senfl=(archvsync)       NOPASSWD: /home/archvsync/bin/runplanet ""
@@ -112,10 +115,10 @@ archvsync stabile=(snapshot)      NOPASSWD: /srv/snapshot.debian.org/bin/update-trigg
 %debian-release        ries=(dak)              /usr/local/bin/dak transitions --import *
 %ftpteam       ries=(dak)              /usr/local/bin/dak transitions --import *
 # security
-%security      klecker=(dak)           NOPASSWD: /usr/local/bin/dak new-security-install -[AR] -- *
-%sec_public    klecker=(dak)           NOPASSWD: /usr/local/bin/dak new-security-install -[AR] -- *
-%sec_data      klecker=(archvsync)     NOPASSWD: /home/archvsync/security/signal ""
-dak            klecker=(archvsync)     NOPASSWD: /home/archvsync/signal_security
+%security      SECHOSTS=(dak)          NOPASSWD: /usr/local/bin/dak new-security-install -[AR] -- *
+%sec_public    SECHOSTS=(dak)          NOPASSWD: /usr/local/bin/dak new-security-install -[AR] -- *
+%sec_data      SECHOSTS=(archvsync)    NOPASSWD: /home/archvsync/security/signal ""
+dak            SECHOSTS=(archvsync)    NOPASSWD: /home/archvsync/signal_security
 # web stuff
 debwww         WEBHOSTS=(archvsync)    NOPASSWD: /home/archvsync/webmirrors/runmirrors
 # more list stuff