Skip to content

Conversation

@andreaso
Copy link
Owner

@andreaso andreaso commented Nov 17, 2025

With the #56 change to one shared login user it doesn't make as much sense to have individual per zone sudoers rules. Also, the rndc and knotc subcommands are narrow enough that I really don't see any real room for wildcard abuse.

On the upside, this simplification takes away the need to rerun the szh-sudoers command any time a zones gets added to the zone-handler.yaml config file.

With the 2562b1a change to one shared login user it doesn't make as
much sense to have individual per zone sudoers rules. Also, the rndc
and knotc subcommands are narrow enough that I really don't see any
real room for wildcard abuse.

On the upside, this simplification takes away the need to rerun the
_szh-sudoers_ command any time a zones gets added to the
_zone-handler.yaml_ config file.
@andreaso andreaso merged commit 435271f into main Nov 17, 2025
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant