How can I apply the principle of least privilege to Bash scripts on a Linux system?
0 reputation · 10 Jan 2022, 00:31 UTC
0 reputation · 10 Jan 2022, 00:31 UTC
When writing Bash scripts that perform administrative tasks, how can I restrict the script’s capabilities to only the operations it truly needs, following the principle of least privilege? For example, if a script only needs to read specific log files and write to a designated directory, what steps should I take to set up a dedicated non‑root user, adjust file system permissions, and use tools like sudo with restricted command lists or Linux capabilities to confine the script’s execution environment? Please explain the configuration process, verification methods, and rollback procedures in case the restrictions break functionality.
Note: The supplied sources discuss WSL installation and troubleshooting, not Bash least‑privilege hardening, so the answer should rely on general Linux security best practices.
26525 reputation · 10 Jan 2022, 07:27 UTC
To confine a Bash script to only the operations it truly needs, create a dedicated non‑root user, lock down filesystem permissions, and use a tightly scoped sudoers entry for any privileged commands. Verify the setup by running the script as that user and checking what it can actually do; if something breaks, revert the changes.
sudo adduser --system --group --no-create-home scriptuser
sudo chown root:scriptuser /opt/myscript/myscript.sh
sudo chmod 750 /opt/myscript/myscript.sh
sudo chown root:adm /var/log/myapp/*
sudo chmod 640 /var/log/myapp/*
sudo mkdir -p /var/lib/myapp/output
sudo chown scriptuser:scriptuser /var/lib/myapp/output
sudo chmod 750 /var/lib/myapp/output
# Use visudo to edit safely
sudo visudo
# Add a line like:
scriptuser ALL=(root) NOPASSWD: /usr/bin/customtool --option
Replace /usr/bin/customtool --option with the exact command and arguments the script needs to run with elevated privileges.
#!/usr/bin/env bash
set -euo pipefail # abort on error, unset var, or failed pipe
umask 027 # new files: owner rwx, group rx, others none
# Example of using sudo for the privileged step
if ! sudo /usr/bin/customtool --option; then
echo \"Privileged step failed\" >&2
exit 1
fi
# Rest of script runs as scriptuser, accessing only the pre‑set paths
sudo -u scriptuser /opt/myscript/myscript.sh
sudo -l -U scriptuser
Only the intended command should appear.
ls -l /opt/myscript/myscript.sh
ls -l /var/log/myapp/*
ls -ld /var/lib/myapp/output
sudo deluser --remove-home scriptuser
sudo delgroup scriptuser
# Remove any leftover directories or adjust permissions as needed
sudo chown root:adm /var/log/myapp/*
sudo chmod 640 /var/log/myapp/*
sudo chown root:root /var/lib/myapp/output
sudo chmod 755 /var/lib/myapp/output
The steps assume the script’s required privileged operation can be expressed as a single, non‑interactive command (or a small set of commands) that is safe to allow via sudo. If the script needs to run a complex suite of binaries or edit files in multiple locations, further refinement of the sudoers rule or use of Linux capabilities/containers may be necessary. In such cases, please provide the exact list of privileged actions so the sudoers entry can be tightened accordingly.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.