Files
mesh-catalog/modules/sudo/module.json
T
jochen f015aba34a sudo: declare the operator account's passwordless escalation as a module
Three modules' tools act through `sudo -n` and nothing declared that the
account may; each machine said so in a hand-set line in /etc/sudoers. The
module owns the package and /etc/sudoers.d/10-mesh-operator (0440), checked
by visudo in its manifest test, and serves sudo_rules, sudo_check and
sudo_drop_ins from a Go bundle. lab stops declaring the sudo package, which
would collide with this module on the node that runs both (hq ADR 0207,
to-be 42 Phase 1).
2026-10-04 12:50:20 +02:00

42 lines
1.2 KiB
JSON

{
"module": "sudo",
"version": "1",
"capabilities": [
"package-manager"
],
"tools": [
"sudo_rules",
"sudo_check",
"sudo_drop_ins"
],
"resources": [
{
"id": "package",
"type": "package",
"package": "sudo"
},
{
"id": "operator",
"type": "file",
"path": "/etc/sudoers.d/10-mesh-operator",
"mode": "0440",
"content": "# The mesh's (module sudo, novox/hq to-be 42, research 027): the operator account escalates\n# without a prompt. The mesh's tools that act as root run `sudo -n` as this account and rely on it;\n# until this file, every machine said so only in a line set by hand in /etc/sudoers.\n# Written whole at every push: an edit here is overwritten. A file of this directory whose name\n# holds a dot or ends in ~ is not read by sudo; this name holds neither.\n${machine:account} ALL=(ALL:ALL) NOPASSWD: ALL\n"
}
],
"build": {
"artifacts": [
{
"name": "tools",
"kind": "bundle",
"language": "go",
"system": "arch",
"from": "cmd/sudo-tools",
"binary": "sudo-tools",
"loads": [
"sudo-tools"
]
}
]
}
}