# OpenRemedy Client — limited NOPASSWD sudo for automated remediation
openremedy-client ALL=(ALL) NOPASSWD: /usr/bin/systemctl start *, /usr/bin/systemctl stop *, /usr/bin/systemctl restart *, /usr/bin/systemctl reload *, /usr/bin/systemctl enable *, /usr/bin/systemctl disable *, /usr/bin/systemctl status *, /usr/bin/systemctl is-active *, /usr/bin/systemctl is-enabled *, /usr/bin/systemctl daemon-reload
openremedy-client ALL=(ALL) NOPASSWD: /usr/bin/dnf *, /usr/bin/yum *, /usr/bin/rpm *, /bin/rpm *
openremedy-client ALL=(ALL) NOPASSWD: /usr/bin/journalctl *, /usr/sbin/logrotate *
openremedy-client ALL=(ALL) NOPASSWD: /usr/bin/cp *, /usr/bin/mv *, /usr/bin/chmod *, /usr/bin/chown *, /usr/bin/rm *
openremedy-client ALL=(ALL) NOPASSWD: /usr/bin/firewall-cmd *
openremedy-client ALL=(ALL) NOPASSWD: /usr/bin/docker *
openremedy-client ALL=(ALL) NOPASSWD: /usr/bin/certbot *
openremedy-client ALL=(ALL) NOPASSWD: /usr/bin/kill *, /usr/bin/killall *
openremedy-client ALL=(ALL) NOPASSWD: /usr/bin/setup, /usr/bin/facter
