sudoers file optional command arguments

Viewed 500

I'm trying to restrict systemctl command to allow sudoers to perform some modification commands (e.g. stop/stop/restart) on a specified unit (e.g. me.service), while allowing any number of systemctl options (e.g. --no-block/--force/--reverse/-f etc.)

If regexp was allowed, this is kind of what I want:

%group-one ALL=(root) /bin/systemctl ([-][-]*[[:alpha:]]+)* start me.service

But obviously I only have POSIX glob to work with.

I want to avoid typing out each and every permutation of systemctl options there is to replace that regexp. I am also open to using a script mectl that wraps the systemctl to do what I want.

There must be some good solutions to lock down some arguments of a command during sudo but not others. How would you solve it?

TIA

0 Answers
Related