# HAPX-UI — privilege grant for the CrowdSec setup wizard. # # Install as /etc/sudoers.d/hapx-ui-crowdsec, mode 0440, owner root:root, verify: # visudo -cf /etc/sudoers.d/hapx-ui-crowdsec # # The web service (unprivileged user hapx-ui) is granted exactly: # - `hapx-ui-crowdsec preflight`: a read-only status probe (no state change). # - starting the setup oneshot (hapx-ui-crowdsec-setup.service): install + # configure CrowdSec as root in its own cgroup. # # The setup verb takes NO arguments — mode/token flow only through the # strictly-validated request file /var/lib/hapx-ui/crowdsec-setup-request.json. # The helper (/usr/local/sbin/hapx-ui-crowdsec, root:root 0755, not writable by # hapx-ui) and the unit's ExecStart are fixed, so this is the entire attack # surface. Both systemctl paths are listed for merged-/usr layouts. hapx-ui ALL=(root) NOPASSWD: /usr/local/sbin/hapx-ui-crowdsec preflight, /usr/bin/systemctl start --no-block hapx-ui-crowdsec-setup.service, /bin/systemctl start --no-block hapx-ui-crowdsec-setup.service