Home › Linux root and sudo security › Step 13
Lesson 13: Keeping sudoers configuration in a Git repository
Step 13 of 13 in Linux root and sudo security · video 4:27
What you will learn
- Four core sudoers best practices
- Keep sudoers role examples in a Git repository
- Refresh a local copy of the course repository
- Re-run an earlier command with history and !N
About this lesson
The series ends by collecting its work in one place. A plain-text best-practices file sums up the rules followed throughout: always edit with visudo, test configurations with visudo -c, keep rules modular in /etc/sudoers.d, and grant the least privilege a job needs. That file, a note on disabling root logins over SSH, and example files for each configuration built earlier (service management, web, database and backup roles, advanced security, environment security and session management) are added to the course's GitHub repository through the web interface. Back on the Linux machine the local copy is refreshed; when the new files do not appear, the folder is removed and cloned again, with history | grep git and !14 used to re-run the earlier clone command without retyping it. Keeping sudoers examples in a repository gives one reusable source of tested rules for the next server or for following the course.
Check yourself
1. Name the four best practices in the lesson's summary file.
Always edit with visudo, test configurations with visudo -c, use /etc/sudoers.d for modular configuration, and follow the principle of least privilege. Together they keep sudoers valid, organised and as narrow as each role allows.
2. What does !14 do in bash?
It re-runs command number 14 from the shell history, as numbered by history. Combined with history | grep git, it is a quick way to repeat a long command such as a git clone.
3. Why keep the sudoers role examples in a Git repository?
The repository holds tested example files in one place, so they can be cloned onto another machine and reused instead of being retyped from memory, and Git keeps a record of every change to them.
4. Before copying an example file from the repository into /etc/sudoers.d on a server, what should you check?
Validate it with sudo visudo -c -f <file> and make sure it ends up owned by root:root with mode 0440. A syntax error or loose permissions can break sudo or cause the file to be rejected.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.
Zero-Trust Linux Administration: Complete Root Sudo Security
Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026
Get the course for $12.99