Skip to content

Grant Least-Privilege Linux Access with Sudoers

Shared administrator accounts make it difficult to tell who performed a privileged action, while unrestricted sudo grants far more access than many support tasks require. A dedicated group and a narrow sudoers rule let operators inspect a named service while keeping other administrative commands restricted.

This example grants members of web-ops permission to view the status and journal for the nginx service. Run the commands as an administrator and adapt the service name and executable paths to your system.


Step 1: Confirm the Account and Command Paths

01

Check the Operator Account and Installed Tools

Preparation

Confirm that the operator account and service exist, and find the absolute paths sudoers will use. This example uses the account operator and service nginx; substitute the names used in your environment.

Terminal window
getent passwd operator
systemctl status nginx --no-pager
command -v systemctl
command -v journalctl
❯ View Expected Console Output
operator:x:1001:1001:Web Operator:/home/operator:/bin/bash
● nginx.service - A high performance web server
Active: active (running)
/usr/bin/systemctl
/usr/bin/journalctl

Step 2: Add a Narrow Sudoers Rule

02

Allow Only Service Status and Log Inspection

Sudoers Policy

Use visudo to create a drop-in file. The rule pins the full argument strings and disables the pager so operators cannot add unreviewed command options or reach an interactive pager. Use the command paths reported on your system in Step 1.

Terminal window
sudo visudo -f /etc/sudoers.d/web-ops

Add this policy to the editor, then save and exit:

%web-ops ALL=(root) /usr/bin/systemctl --no-pager status nginx, /usr/bin/journalctl --no-pager -u nginx

Validate the saved drop-in and its permissions:

Terminal window
sudo visudo -cf /etc/sudoers.d/web-ops
sudo stat -c '%a %U:%G %n' /etc/sudoers.d/web-ops
❯ View Expected Console Output
/etc/sudoers.d/web-ops: parsed OK
440 root:root /etc/sudoers.d/web-ops

Step 3: Create the Group and Add the Operator

03

Assign the Account to the Operations Group

Access Assignment

Create the group and add the existing operator account. The -a option preserves the account’s other supplementary groups. The user must start a new login session for the membership change to take effect.

Terminal window
sudo groupadd --force web-ops
sudo usermod -aG web-ops operator
id operator
❯ View Expected Console Output
uid=1001(operator) gid=1001(operator) groups=1001(operator),1002(web-ops)

Step 4: Review and Verify Effective Permissions

04

Confirm Allowed Commands and Test the New Session

Verification

Review the account’s effective sudo permissions, then sign in as the operator again and test the allowed read-only commands. The policy does not grant permission to restart services or run a general root shell.

Terminal window
sudo -l -U operator

In a fresh session as operator, run:

Terminal window
sudo -l
sudo /usr/bin/systemctl --no-pager status nginx
sudo /usr/bin/journalctl --no-pager -u nginx
❯ View Expected Console Output
User operator may run the following commands on this host:
(root) /usr/bin/systemctl --no-pager status nginx, /usr/bin/journalctl --no-pager -u nginx

Comments