|
|
|
|
|
by nico
162 days ago
|
|
Great pointers, thank you How would you go about allowing something like `ssh user@server "ls somefolder/"` but disallowing `ssh user@server "rm"`? Similarly, allow `ssh user@server "mysql \"SELECT...\""`, but block `ssh user@server "mysql \"[UPDATE|DELETE|DROP|TRUNCATE|INSERT]...\""` ? Ideally in a way that it can provide more autonomy for the agent, so that I need to review fewer commands |
|
I'm not familiar with rbash, but it seems like it can do (at least some of) what you want.