op-mode: T7745: add a CLI for operator user command permissions #4674
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Change summary
Introduces a CLI for creating local operator-level users.
This PR adds the following commands:
set system login operator-group <name> command-policy allow <cmd>— allows creating permission groups that limit operator users to specific sets of commands.set system login user <name> operator group <name>— allows assigning operator-level users to groups.Every operator-level user must be assigned to at least one group. The default config is updated to include a default operator group that allows all commands.
Operator user permissions are saved to a data file at commit time:
The new operational command runner (
/usr/bin/vyos-op-run) then uses that file to check command permissions.This PR does not allow retrieving user level information from remote authentication sources like RADIUS — we'll need to work out the details there.
Types of changes
Related Task(s)
Related PR(s)
How to test / Smoketest result
Checklist: