# HAPX-UI — minimal privilege escalation for the dedicated service user. # # Install as /etc/sudoers.d/hapx-ui with mode 0440, owner root:root, then verify: # visudo -cf /etc/sudoers.d/hapx-ui # # This grants the unprivileged `hapx-ui` user exactly ONE capability: reloading # HAProxy after it has written and validated a new config. It cannot run any # other command as root. The reload code calls `sudo -n systemctl reload # haproxy`; both common systemctl locations are listed so the rule matches # regardless of merged-/usr layout. # # In-app self-update is intentionally NOT covered here — on a hardened native # install, update via apt / package / reinstall, not from the web UI. Cmnd_Alias HAPX_RELOAD = /usr/bin/systemctl reload haproxy, /bin/systemctl reload haproxy hapx-ui ALL=(root) NOPASSWD: HAPX_RELOAD