X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Fsudo%2Ffiles%2Fsudoers;h=e0ca73ec0464f0b943dddfdf27f2e99c6e7765cf;hb=2cc7fc7d745522b4ce944dc6774f8651593d1c4c;hp=c58444240b16aa28384294e51ec9d48f627be6c4;hpb=4700a4c512f049ac4cfae3d7ab27c022a682b53c;p=mirror%2Fdsa-puppet.git diff --git a/modules/sudo/files/sudoers b/modules/sudo/files/sudoers index c58444240..e0ca73ec0 100644 --- a/modules/sudo/files/sudoers +++ b/modules/sudo/files/sudoers @@ -28,13 +28,12 @@ Host_Alias SECHOSTS = seger Host_Alias FTPHOSTS = fasolo Host_Alias ZIVITHOSTS = zelenka, zandonai Host_Alias AACRAIDHOSTS = pettersson -Host_Alias MEGARAIDHOSTS = rautavaara, sibelius +Host_Alias MEGARAIDHOSTS = sibelius Host_Alias LISTHOSTS = bendel Host_Alias BUILDD_MASTER = wuiet Host_Alias PORTERBOXES = abel, asachi, barriere, eller, falla, fischer, harris, minkus, partch, plummer, pizzetti, zelenka Host_Alias PIUPARTS_SLAVE_HOSTS = piu-slave-bm-a Host_Alias MQ_HOSTS = rainier, rapoport -Host_Alias NOVAHOSTS = oyens Host_Alias JENKINSHOSTS = jerea # Cmnd alias specification @@ -45,6 +44,12 @@ root ALL=(ALL) ALL # DSA and local admins %adm ALL=(ALL) ALL + +# XXX +# until march 2017 +93sam acker=(ALL) ALL +kibi acker=(ALL) ALL + %adm ALL=(ALL) NOPASSWD: /usr/bin/apt-get update, /usr/bin/apt-get upgrade, /usr/bin/apt-get dist-upgrade, /usr/bin/apt-get clean, /usr/sbin/samhain -t check -i -p err -s none -l none -m none, /usr/sbin/upgrade-porter-chroots %zivit-admins ZIVITHOSTS=(ALL) NOPASSWD: ALL @@ -130,6 +135,7 @@ nagios storace=(debbackup) NOPASSWD: /usr/lib/nagios/plugins/dsa-check-backuppg %list master=(debian) ALL %manpages ALL=(manpages) ALL %mirroradm ALL=(archvsync) ALL +%mirroradm melartin=(mirroradm) ALL %nm ALL=(nm) ALL %patch-tracker ALL=(patch-tracker) ALL %pet-devel ALL=(pet-devel) ALL @@ -185,6 +191,7 @@ dak FTPHOSTS=(staticsync) NOPASSWD: /usr/local/bin/static-update-component inc dak FTPHOSTS=(staticsync) NOPASSWD: /usr/local/bin/static-update-component metadata.ftp-master.debian.org %publicity dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component bits.debian.org %publicity dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component micronews.debian.org +%mirroradm melartin=(staticsync) NOPASSWD: /usr/local/bin/static-update-component mirror-master.debian.org %debdelta donizetti=(staticsync) NOPASSWD: /usr/local/bin/static-update-component debdeltas.debian.net %webwml master=(staticsync) NOPASSWD: /usr/local/bin/static-update-component network-test.debian.org planet philp=(staticsync) NOPASSWD: /usr/local/bin/static-update-component planet.debian.org @@ -215,6 +222,7 @@ pabs dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component time %debconfstatic dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component miniconf10.debconf.org mini-dak porta=(staticsync) NOPASSWD: /usr/local/bin/static-update-component incoming.ports.debian.org %wbadm wuiet=(staticsync) NOPASSWD: /usr/local/bin/static-update-component apt.buildd.debian.org +%manpages manziarly=(staticsync) NOPASSWD: /usr/local/bin/static-update-component manpages.debian.org # The piuparts slave needs to handle chroots piupartss PIUPARTS_SLAVE_HOSTS=(ALL) NOPASSWD: ALL @@ -227,7 +235,6 @@ letsencrypt denis=(dnsadm) NOPASSWD: /srv/dns.debian.org/bin/update %wbadm BUILDD_MASTER=(root) /usr/local/bin/update-buildd-sshkeys # mirror push dak FTPHOSTS,SECHOSTS=(archvsync) NOPASSWD:/home/archvsync/runmirrors -dak FTHOSTS=(backports) NOPASSWD: /home/backports/bin/update-archive # archvsync triggers snapshot archvsync sibelius=(snapshot) NOPASSWD: /srv/snapshot.debian.org/bin/update-trigger archvsync sibelius=(snapshot) NOPASSWD: /srv/2ndsnapshot/bin/update-trigger @@ -267,20 +274,6 @@ nagiosadm tchaikovsky=(root) NOPASSWD: /usr/sbin/service icinga reload %Debian,%guest,%d-i PORTERBOXES=(root) NOPASSWD: /usr/local/bin/dd-schroot-cmd -# Openstack stuff -Defaults:neutron !requiretty -nova NOVAHOSTS=(root) NOPASSWD: /usr/bin/nova-rootwrap * -neutron NOVAHOSTS=(root) NOPASSWD: /usr/bin/neutron-rootwrap /etc/neutron/rootwrap.conf * -cinder NOVAHOSTS=(root) NOPASSWD: /usr/bin/cinder-rootwrap /etc/cinder/rootwrap.conf * -%openstack NOVAHOSTS=(keystone) ALL -%openstack NOVAHOSTS=(memcache) ALL -%openstack NOVAHOSTS=(ceilometer) ALL -%openstack NOVAHOSTS=(cinder) ALL -%openstack NOVAHOSTS=(glance) ALL -%openstack NOVAHOSTS=(heat) ALL -%openstack NOVAHOSTS=(neutron) ALL -%openstack NOVAHOSTS=(nova) ALL - # ports stuff mini-dak porta=(archvsync) NOPASSWD: /home/archvsync/signal_ports mini-dak porta=(archvsync) NOPASSWD: /home/archvsync/signal_ports-cd