Q: A junior admin needs root access for specific commands only (restarting services, reading logs), not full unrestricted root access. How do you configure granular sudo access?
The /etc/sudoers file (edited exclusively via visudo to prevent syntax errors) controls which users can run which commands as root.
#Linux #Linux / SRE — Scenario-Based Interview Questions #L2 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""In an interview, I explain my systematic Linux troubleshooting methodology using Brendan Gregg's USE method. The interviewer is testing: Sudoers configuration, principle of least privilege.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
The /etc/sudoers file (edited exclusively via visudo to prevent syntax errors) controls which users can run which commands as root.
ALL=(root): Can execute on any host as the root user.NOPASSWD:: Don't prompt for password (useful for automation).- Specific commands: Only the exact commands listed are allowed. Running
sudo bashorsudo suwould be denied. - Use command aliases for grouping:
2️⃣
Remediation & Permanent Safeguards
To grant granular access: Key directives: Best practices:
# Allow user 'deploy' to restart nginx and read syslog only
deploy ALL=(root) NOPASSWD: /bin/systemctl restart nginx, /bin/systemctl status nginx, /usr/bin/journalctl -u nginx
- Use group-based rules:
%devops ALL=(root) NOPASSWD: WEB_MGMTapplies to all users in thedevopsgroup. - Never use
ALL=(ALL) ALLfor non-admin users—it grants full unrestricted root access.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: ALL=(root): Can execute on any host as the root user.."
⚡ 60-Second Elevator Pitch Talking Points
- ALL=(root): Can execute on any host as the root user.
- NOPASSWD:: Don't prompt for password (useful for automation).
- Specific commands: Only the exact commands listed are allowed. Running sudo bash or sudo su would...
Advertisement