pyrocufflink: Configure sudo for server admins
Members of the *Server Admins* AD group need to be able to use `sudo` for privilege elevation on all domain member servers.
This commit is contained in:
@@ -3,8 +3,16 @@
|
|||||||
- winbind
|
- winbind
|
||||||
- nsswitch
|
- nsswitch
|
||||||
- system-auth
|
- system-auth
|
||||||
|
- sudo
|
||||||
tasks:
|
tasks:
|
||||||
- name: ensure winbind is running
|
- name: ensure winbind is running
|
||||||
service:
|
service:
|
||||||
name=winbind
|
name=winbind
|
||||||
state=started
|
state=started
|
||||||
|
- name: ensure server admins can use sudo
|
||||||
|
copy:
|
||||||
|
dest: /etc/sudoers.d/20_server-admins
|
||||||
|
content: |
|
||||||
|
%server\ admins ALL=(ALL) ALL
|
||||||
|
mode: '0440'
|
||||||
|
validate: visudo -cf %s
|
||||||
|
|||||||
Reference in New Issue
Block a user