Grant Least-Privilege Linux Access with Sudoers
Shared administrator accounts make it difficult to tell who performed a privileged action, while unrestricted sudo grants far more access than many support tasks require. A dedicated group and a narrow sudoers rule let operators inspect a named service while keeping other administrative commands restricted.
This example grants members of web-ops permission to view the status and journal for the nginx service. Run the commands as an administrator and adapt the service name and executable paths to your system.
Step 1: Confirm the Account and Command Paths
Check the Operator Account and Installed Tools
PreparationConfirm that the operator account and service exist, and find the absolute paths sudoers will use. This example uses the account operator and service nginx; substitute the names used in your environment.
getent passwd operatorsystemctl status nginx --no-pagercommand -v systemctlcommand -v journalctl❯ View Expected Console Output
operator:x:1001:1001:Web Operator:/home/operator:/bin/bash● nginx.service - A high performance web server Active: active (running)/usr/bin/systemctl/usr/bin/journalctlStep 2: Add a Narrow Sudoers Rule
Allow Only Service Status and Log Inspection
Sudoers PolicyUse visudo to create a drop-in file. The rule pins the full argument strings and disables the pager so operators cannot add unreviewed command options or reach an interactive pager. Use the command paths reported on your system in Step 1.
sudo visudo -f /etc/sudoers.d/web-opsAdd this policy to the editor, then save and exit:
%web-ops ALL=(root) /usr/bin/systemctl --no-pager status nginx, /usr/bin/journalctl --no-pager -u nginxValidate the saved drop-in and its permissions:
sudo visudo -cf /etc/sudoers.d/web-opssudo stat -c '%a %U:%G %n' /etc/sudoers.d/web-ops❯ View Expected Console Output
/etc/sudoers.d/web-ops: parsed OK440 root:root /etc/sudoers.d/web-opsStep 3: Create the Group and Add the Operator
Assign the Account to the Operations Group
Access AssignmentCreate the group and add the existing operator account. The -a option preserves the account’s other supplementary groups. The user must start a new login session for the membership change to take effect.
sudo groupadd --force web-opssudo usermod -aG web-ops operatorid operator❯ View Expected Console Output
uid=1001(operator) gid=1001(operator) groups=1001(operator),1002(web-ops)Step 4: Review and Verify Effective Permissions
Confirm Allowed Commands and Test the New Session
VerificationReview the account’s effective sudo permissions, then sign in as the operator again and test the allowed read-only commands. The policy does not grant permission to restart services or run a general root shell.
sudo -l -U operatorIn a fresh session as operator, run:
sudo -lsudo /usr/bin/systemctl --no-pager status nginxsudo /usr/bin/journalctl --no-pager -u nginx❯ View Expected Console Output
User operator may run the following commands on this host: (root) /usr/bin/systemctl --no-pager status nginx, /usr/bin/journalctl --no-pager -u nginx