Q: Standard Unix permissions (owner/group/other) are insufficient for your use case. You need one specific user to have read access to a file without changing the file's owner or group. How do you accomplish this?
POSIX ACLs (Access Control Lists) extend the traditional owner/group/other permission model by allowing per-user and per-group rules on f...
#Linux #Allow user 'deploy' to restart nginx and read syslog only #L2 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""In an interview, I explain my systematic Linux troubleshooting methodology using Brendan Gregg's USE method. The interviewer is testing: POSIX Access Control Lists (ACLs), fine-grained permissions.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
POSIX ACLs (Access Control Lists) extend the traditional owner/group/other permission model by allowing per-user and per-group rules on files and directories.
- Set ACL:
setfacl -m u:username:rwx file - Set default ACL (inherited by new files):
setfacl -d -m u:alice:rx /var/data/ - Remove ACL:
setfacl -x u:alice file
2️⃣
Remediation & Permanent Safeguards
To grant a specific user read access: To verify: Output: Key commands: Note: The filesystem must be mounted with ACL support (most modern ext4/XFS filesystems enable this by default). A + symbol appears in ls -l output when ACLs are set (e.g., -rw-r--r--+).
setfacl -m u:alice:r /var/data/report.csv
- Remove all ACLs:
setfacl -b file
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Set ACL: setfacl -m u:username:rwx file."
⚡ 60-Second Elevator Pitch Talking Points
- Set ACL: setfacl -m u:username:rwx file
- Set default ACL (inherited by new files): setfacl -d -m u:alice:rx /var/data/
- Remove ACL: setfacl -x u:alice file
Advertisement