Create a secure, role-based sudo model granting controlled
administrative privileges while preventing log tampering and enabling
full command auditing.
sudo groupadd sysadmins
sudo usermod -aG sysadmins alice
Check group membership:
groups alice
Edit the file:
sudo visudo -f /etc/sudoers.d/sysadmins
Paste the following configuration:
# Package Management Command Alias
Cmnd_Alias PKG_MGMT = /usr/bin/apt update, \
/usr/bin/apt upgrade, \
/usr/bin/apt install *, \
/usr/bin/apt remove *, \
/usr/bin/apt autoremove
# Grant Limited Sudo Privileges to sysadmins
%sysadmins ALL=(ALL) PKG_MGMT
This configuration allows sysadmins to: - Update and upgrade the
system - Install and remove packages
It does NOT allow: - Editing the sudoers file - Managing users -
Changing firewall rules - Deleting logs
Ensure the user is not part of the adm or systemd-journal groups to
prevent direct log browsing access.
Protect critical logs using immutable attributes:
sudo chattr +i /var/log/auth.log
sudo chattr +i /var/log/syslog
sudo chattr +i /var/log/sudo.log
To remove immutable attribute:
sudo chattr -i /var/log/syslog
Edit the main sudoers file:
visudo
Append the following:
Defaults logfile="/var/log/sudo.log"
Defaults log_input
Defaults log_output
Defaults use_pty
This ensures: - Every sudo command is logged - Input typed by sysadmins
is recorded - Output displayed by the system is recorded - Sessions are
executed within a secure pseudo-terminal
Allow SSH only from the sysadmin laptop over WireGuard:
sudo ufw allow in on wg0 from 10.44.0.2 to any port 22
sudo ufw deny in on wg0 to any port 22
This restricts VPN SSH access to the server to only the authorized
sysadmin device (10.44.0.2).
This project successfully implemented a secure, role-based
administrative access model using the principle of least privilege and
layered security controls.
A dedicated sysadmins group was created and configured with restricted
sudo permissions limited to package management tasks, preventing full
root access and reducing the risk of privilege abuse.
Critical log files were protected against tampering, enhanced sudo
logging was enabled to record command execution, input, and output, and
auditing mechanisms were implemented to provide full visibility into
privileged activity.
Overall, this design establishes a controlled, auditable, and
security-focused administrative framework aligned with modern
infrastructure security best practices.