X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Fsudo%2Ffiles%2Fsudoers;h=0f2f9597751390d485c0137b4864ee022066f086;hb=a6d02ccf671969745b2b8dc767f93ed485b2e80a;hp=e6ff9443bf0e45be5611f0b13c1626cb95d74983;hpb=0b574f07d6e5276dc368feeca12cabe0fbc64020;p=mirror%2Fdsa-puppet.git diff --git a/modules/sudo/files/sudoers b/modules/sudo/files/sudoers index e6ff9443b..0f2f95977 100644 --- a/modules/sudo/files/sudoers +++ b/modules/sudo/files/sudoers @@ -21,6 +21,8 @@ Defaults env_reset Defaults passprompt="[sudo] password for %u on %h: " Defaults secure_path="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" +Defaults>archvsync secure_path="/home/archvsync/bin:/usr/local/bin:/usr/bin:/bin" + # Host alias specification Host_Alias VOIPHOSTS = vogler Host_Alias WEBHOSTS = wolkenstein @@ -31,7 +33,7 @@ Host_Alias AACRAIDHOSTS = pettersson Host_Alias MEGARAIDHOSTS = sibelius Host_Alias LISTHOSTS = bendel Host_Alias BUILDD_MASTER = wuiet -Host_Alias PORTERBOXES = abel, asachi, barriere, eller, falla, fischer, harris, minkus, partch, plummer, pizzetti, zelenka +Host_Alias PORTERBOXES = abel, amdahl, asachi, barriere, eller, falla, fischer, harris, minkus, partch, plummer, pizzetti, zelenka Host_Alias PIUPARTS_SLAVE_HOSTS = piu-slave-bm-a, piu-slave-ubc-01 Host_Alias MQ_HOSTS = rainier, rapoport Host_Alias JENKINSHOSTS = jerea @@ -105,6 +107,14 @@ nagios storace=(debbackup) NOPASSWD: /usr/lib/nagios/plugins/dsa-check-backuppg %debconfstatic ALL=(debconfstatic) ALL %debdelta ALL=(debdelta) ALL %debian-cd ALL=(debian-cd) ALL +%cloud-build ALL=(cloud-build) ALL +%cloud-ci ALL=(cloud-ci) ALL +%cloud-test ALL=(cloud-test) ALL +%cloud-deploy-aws ALL=(cloud-deploy-aws) ALL +%cloud-deploy-azure ALL=(cloud-deploy-azure) ALL +%cloud-deploy-gce ALL=(cloud-deploy-gce) ALL +%cloud-deploy-openstack ALL=(cloud-deploy-openstack) ALL +%cloud-deploy-digitalocean ALL=(cloud-deploy-digitalocean) ALL %debian-i18n ALL=(debian-i18n) ALL %debian-r ALL=(debian-r) ALL %debian-r ALL=(debian-r-wb-buildd) ALL @@ -119,7 +129,7 @@ nagios storace=(debbackup) NOPASSWD: /usr/lib/nagios/plugins/dsa-check-backuppg %forums ALL=(forums) ALL %gitdoadm ALL=(gitdoadm) ALL # the git user also exists on adayevskaya where it's a different service.. -%gitdoadm gigault=(git) ALL +%gitdoadm godard=(git) ALL %keyring ALL=(keyring) ALL %jenkins-adm ALL=(jenkins-adm) ALL %lintian ALL=(lintian) ALL @@ -157,6 +167,7 @@ nagios storace=(debbackup) NOPASSWD: /usr/lib/nagios/plugins/dsa-check-backuppg %dacshelper diabelli=(www-data) ALL %debsso diabelli=(debsso) ALL %debsso-web diabelli=(debsso-web) ALL +%debconf-web debussy=(debconf-web) ALL # the dak user gets to run stuff as dak-unpriv (for things like lintian checks) %ftptrainee FTPHOSTS=(dak-unpriv) NOPASSWD: /usr/bin/lintian @@ -210,6 +221,8 @@ pabs dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component time %debconfstatic dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component debconf6.debconf.org %debconfstatic dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component debconf7.debconf.org %debconfstatic dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component debconf16.debconf.org +%debconfstatic dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component debconf17.debconf.org +%debconfstatic dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component debconf18.debconf.org %debconfstatic dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component es.debconf.org %debconfstatic dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component fr.debconf.org %debconfstatic dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component miniconf10.debconf.org @@ -248,10 +261,11 @@ debwww WEBHOSTS=(archvsync) NOPASSWD: /home/archvsync/webmirrors/runmirrors %d-i WEBHOSTS=(debwww) /srv/www.debian.org/update-part devel/debian-installer %d-i WEBHOSTS=(debwww) /srv/www.debian.org/cron/lessoften-parts/1installation-guide # more list stuff +%list LISTHOSTS=(postfix) /usr/sbin/postcat %list LISTHOSTS=(root) /usr/sbin/postfix reload -%list stockhausen=(root) /usr/sbin/service jetty restart %list LISTHOSTS=(root) /usr/sbin/qshape, /usr/sbin/postsuper -%list LISTHOSTS=(root) /etc/init.d/spamassassin, /etc/init.d/amavis +%list LISTHOSTS=(root) /usr/sbin/service spamassassin restart, /usr/sbin/service spamassassin reload, /usr/sbin/service spamassassin stop, /usr/sbin/service spamassassin start +%list LISTHOSTS=(root) /usr/sbin/service amavis restart, /usr/sbin/service amavis reload, /usr/sbin/service amavis stop, /usr/sbin/service amavis start %list LISTHOSTS=(amavis) NOPASSWD: /usr/bin/sa-learn %list LISTHOSTS=(amavis) ALL # geodns may reload bind @@ -271,7 +285,6 @@ nagiosadm tchaikovsky=(root) NOPASSWD: /usr/sbin/service icinga reload # ports stuff mini-dak porta=(archvsync) NOPASSWD: /home/archvsync/signal_ports -mini-dak porta=(archvsync) NOPASSWD: /home/archvsync/signal_ports-cd # temporary, for debugging thijs klecker=(root) /usr/sbin/tcpdump