⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] Linux Allow user 'deploy' to restart nginx and read syslog only Production Scenario [L2]

Q: Standard Unix permissions (owner/group/other) are insufficient for your use case. You need one specific user to have read access to a file without changing the file's owner or group. How do you accomplish this?

POSIX ACLs (Access Control Lists) extend the traditional owner/group/other permission model by allowing per-user and per-group rules on f...

#Linux #Allow user 'deploy' to restart nginx and read syslog only #L2 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""In an interview, I explain my systematic Linux troubleshooting methodology using Brendan Gregg's USE method. The interviewer is testing: POSIX Access Control Lists (ACLs), fine-grained permissions.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Initial Diagnostics & Root Cause Analysis

POSIX ACLs (Access Control Lists) extend the traditional owner/group/other permission model by allowing per-user and per-group rules on files and directories.

  • Set ACL: setfacl -m u:username:rwx file
  • Set default ACL (inherited by new files): setfacl -d -m u:alice:rx /var/data/
  • Remove ACL: setfacl -x u:alice file
2️⃣

Remediation & Permanent Safeguards

To grant a specific user read access: To verify: Output: Key commands: Note: The filesystem must be mounted with ACL support (most modern ext4/XFS filesystems enable this by default). A + symbol appears in ls -l output when ACLs are set (e.g., -rw-r--r--+).

setfacl -m u:alice:r /var/data/report.csv
  • Remove all ACLs: setfacl -b file
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Set ACL: setfacl -m u:username:rwx file."
⚡ 60-Second Elevator Pitch Talking Points
  • Set ACL: setfacl -m u:username:rwx file
  • Set default ACL (inherited by new files): setfacl -d -m u:alice:rx /var/data/
  • Remove ACL: setfacl -x u:alice file
Advertisement
Want more Linux scenarios?
Explore our complete collection of scenario-based Linux interview runbooks.
Browse All Linux Questions →

📚 Related Production Scenarios in Linux