summaryrefslogtreecommitdiffstats
path: root/etc/sudoers.d/jenkins
blob: acb0d1422621515b808a56af0f5e834bf5739aa0 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
jenkins ALL=  \
	NOPASSWD: /usr/sbin/debootstrap *, \
	/usr/bin/tee /chroots/*, \
	/usr/bin/tee -a /chroots/*, \
	/usr/bin/tee /etc/schroot/chroot.d/jenkins*, \
	/bin/chmod +x /chroots/*, \
	/usr/sbin/chroot /chroots/*, \
	/usr/sbin/chroot /media/*, \
	/bin/ls -la /media/*, \
	/bin/rm -rf --one-file-system /chroots/*, \
	/bin/rm -rf --one-file-system /schroots/*, \
	/bin/mv /chroots/* /schroots/*, \
	/bin/mv /schroots/* /schroots/*, \
	/bin/umount -l /chroots/*, \
	/bin/umount -l /media/*, \
	/bin/mount -o loop*, \
	/bin/mount --bind *, \
	/usr/bin/du *, \
	/bin/kill -9 *, \
	/usr/bin/file *, \
	/bin/dd if=/dev/zero of=/dev/jenkins*, \
	/usr/bin/qemu-system-x86_64 *, \
	/usr/bin/qemu-img *, \
	/sbin/lvcreate *, /sbin/lvremove *, \
	/bin/mkdir -p /media/*, \
	/usr/bin/guestmount *, \
	/bin/cp -r /media/*, \
	/bin/chown -R jenkins\:jenkins /var/lib/jenkins/jobs/*,\
	SETENV: NOPASSWD: /usr/sbin/pbuilder *, \
	/bin/mv pbuilder/base-reproducible-new.tgz /var/cache/pbuilder/base-reproducible.tgz, \
	/bin/rm /var/cache/pbuilder/base*.tgz, \
	/bin/rm /var/cache/pbuilder/result/*, \
	/usr/bin/dcmd rm *.changes, \
	/usr/bin/dcmd rm -f *.dsc, \
	/usr/bin/apt-get update

# keep these environment variables
Defaults        env_keep += "http_proxy", env_reset