I'm trying to restrict systemctl command to allow sudoers to perform some modification commands (e.g. stop/stop/restart) on a specified unit (e.g. me.service), while allowing any number of systemctl options (e.g. --no-block/--force/--reverse/-f etc.)
If regexp was allowed, this is kind of what I want:
%group-one ALL=(root) /bin/systemctl ([-][-]*[[:alpha:]]+)* start me.service
But obviously I only have POSIX glob to work with.
I want to avoid typing out each and every permutation of systemctl options there is to replace that regexp. I am also open to using a script mectl that wraps the systemctl to do what I want.
There must be some good solutions to lock down some arguments of a command during sudo but not others. How would you solve it?
TIA