sudoers can constrain the invoking user, target identity, executable path, and command arguments. A wildcard argument, editor, pager, interpreter, or script writable by the caller may let the user escape into another command. The rule also depends on environment handling and executable integrity. A safe maintenance workflow prefers a small root-owned helper that validates inputs and performs one narrow operation, while the policy allows only that helper under the required identity. Exact path matching does not prove that a mutable program or its imported files are safe. Review the effective policy for the actual operator identity and group memberships.
sudo policy: authorize an exact maintenance action, not a path to a shell
Operational decision
A search-index responder needs to rotate one local service log, not administer the entire host. Instead of giving sudo access to a shell, text editor, or arbitrary systemctl arguments, the team creates a root-owned helper that accepts the fixed service name, checks the log destination, and records the ticket ID. The sudo rule grants that helper to the responder group. On a disposable host, testers try the approved invocation, an extra argument, a service-name substitution, a writable helper replacement, and a pager or environment escape. Each unauthorized path must fail while the approved operation succeeds. The rule and helper are versioned together so review sees the full authority being granted.
Allowed action: /usr/local/sbin/rotate-search-index-log
Target identity: root
Caller group: search-responders
Rejected: arbitrary unit name, shell, editor, extra arguments
Evidence: sudo -l, visudo -c, allowed and denied probesCost and verification
A narrow helper adds a small amount of maintained code, but reduces the incident scope of a stolen operator credential. A single broad sudo rule is cheaper to write and much more expensive to audit or contain. Record accepted and rejected probes in CI or a disposable host, then re-run them when the helper or its dependencies change. Capture sudo's command log without writing credentials or sensitive payloads into arguments. If the operation itself allows user-controlled file paths, root ownership of the helper does not make the input safe.
Common Mistakes
- Do not grant a general shell to avoid writing a constrained maintenance action.
- Do not trust exact executable paths when the file or its imports are operator-writable.
- Do not assume an editor or pager is a read-only command under sudo.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Break-glass access: recover control without permanent privilege
- Cloud policy decisions: trace every authorization layer
- Audit trails: prove which data-plane actions are recorded
- Linux kernel rollouts: prove the running kernel after each reboot cohort
- SSH host-key rotation: change server identity without teaching clients to ignore warnings
