Skip to content

Commit

Permalink
[sudoers] add /usr/local/bin/storyteller to READ_ONLY_CMDS (sonic…
Browse files Browse the repository at this point in the history
…-net#13422)

Adding /usr/local/bin/storyteller to READ_ONLY_CMDS. So no write access or prompt for password is needed to run storyteller.

Tested on 202205 clusters, user who didn't request write access was able to grep log using storyteller.

sign-off: Jing Zhang zhangjing@microsoft.com
  • Loading branch information
zjswhhh authored and mssonicbld committed Feb 7, 2023
1 parent f9d0f25 commit 5b64d82
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion files/image_config/sudoers/sudoers
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,8 @@ Cmnd_Alias READ_ONLY_CMDS = /bin/cat /var/log/syslog*, \
/usr/local/bin/pcieutil *, \
/usr/local/bin/psuutil *, \
/usr/local/bin/sonic-installer list, \
/usr/local/bin/sfputil show *
/usr/local/bin/sfputil show *, \
/usr/local/bin/storyteller *


Cmnd_Alias PASSWD_CMDS = /usr/local/bin/config tacacs passkey *, \
Expand Down

0 comments on commit 5b64d82

Please sign in to comment.