Home › Linux root and sudo security › Step 13

Lesson 13: Keeping sudoers configuration in a Git repository

Step 13 of 13 in Linux root and sudo security · video 4:27

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

The series ends by collecting its work in one place. A plain-text best-practices file sums up the rules followed throughout: always edit with visudo, test configurations with visudo -c, keep rules modular in /etc/sudoers.d, and grant the least privilege a job needs. That file, a note on disabling root logins over SSH, and example files for each configuration built earlier (service management, web, database and backup roles, advanced security, environment security and session management) are added to the course's GitHub repository through the web interface. Back on the Linux machine the local copy is refreshed; when the new files do not appear, the folder is removed and cloned again, with history | grep git and !14 used to re-run the earlier clone command without retyping it. Keeping sudoers examples in a repository gives one reusable source of tested rules for the next server or for following the course.

Good to know: keep only example files in a public repository. Real sudoers files reveal user names, host names and command paths, so they belong in a private one.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Name the four best practices in the lesson's summary file.

Always edit with visudo, test configurations with visudo -c, use /etc/sudoers.d for modular configuration, and follow the principle of least privilege. Together they keep sudoers valid, organised and as narrow as each role allows.

2. What does !14 do in bash?

It re-runs command number 14 from the shell history, as numbered by history. Combined with history | grep git, it is a quick way to repeat a long command such as a git clone.

3. Why keep the sudoers role examples in a Git repository?

The repository holds tested example files in one place, so they can be cloned onto another machine and reused instead of being retyped from memory, and Git keeps a record of every change to them.

4. Before copying an example file from the repository into /etc/sudoers.d on a server, what should you check?

Validate it with sudo visudo -c -f <file> and make sure it ends up owned by root:root with mode 0440. A syntax error or loose permissions can break sudo or cause the file to be rejected.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 12: Cleaning up sudoers and removing test usersPath complete - back to Linux root and sudo security →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.