From b5c5034c5efc9b1ee0903df4da6e0b773d427b15 Mon Sep 17 00:00:00 2001 From: Nicolas Vigier Date: Mon, 7 Feb 2011 18:43:41 +0000 Subject: add sudoers config to allow schedbot to run mga-signpackage as signbot --- modules/buildsystem/manifests/init.pp | 4 ++++ modules/buildsystem/templates/sudoers.signpackage | 1 + 2 files changed, 5 insertions(+) create mode 100644 modules/buildsystem/templates/sudoers.signpackage (limited to 'modules') diff --git a/modules/buildsystem/manifests/init.pp b/modules/buildsystem/manifests/init.pp index 4b360f51..83789592 100644 --- a/modules/buildsystem/manifests/init.pp +++ b/modules/buildsystem/manifests/init.pp @@ -73,6 +73,10 @@ class buildsystem { batchdir => "$sign_home_dir/batches", keydir => "$sign_home_dir/keys", } + + sudo::sudoers_config { "signpackage": + content => template("buildsystem/sudoers.signpackage") + } } class scheduler { diff --git a/modules/buildsystem/templates/sudoers.signpackage b/modules/buildsystem/templates/sudoers.signpackage new file mode 100644 index 00000000..85774716 --- /dev/null +++ b/modules/buildsystem/templates/sudoers.signpackage @@ -0,0 +1 @@ +<%= build_login %> ALL =(<%= sign_login %>) NOPASSWD: /usr/bin/mga-signpackage -- cgit v1.2.1