Joined May 2011
·

Jérémy Lecour

Autrement SAS
·
Marseille, France
·
·
·

I like being able to invoke Monit from my deploy user, but like you I don't want to type a password.

So I've put this user in the sudoers list like this :

Cmnd_Alias MONIT = /usr/bin/monit
my_user ALL=(ALL) NOPASSWD: MONIT

This way I can use sudo without a password but only for Monit.

That said, I also like your solution for better separation between Monit supervised services. With my approach, anybody who has access to Monit can mess with all the services. With your approach it's possible to limit users to specific services since they can be restricted to their parent directories.

Achievements
80 Karma
0 Total ProTip Views