# /etc/sudoers.d file allowing privileged cli commands
Cmnd_Alias  ADMINNSXCLITOOLS = /etc/init.d/nsx-mp-api-server restart, \
    /etc/init.d/nsx-km-api-server restart, \
    /etc/init.d/nsx-edge-api-server restart, \
    /bin/rm -f /image/.can_rollback, \
    /bin/rm -rf /image/nsx_cli_support_bundle_*, \
    /usr/bin/touch /image/.resume_rollback, \
    /opt/vmware/nsx-cli/bin/scripts/swap_partitions, \
    /opt/vmware/nsx-cli/bin/scripts/ipt_rule_action.sh, \
    /opt/vmware/nsx-cli/bin/scripts/config_data_archiver, \
    /bin/mv /tmp/moot-server /etc/default/moot-server, \
    /bin/nc *, \
    /bin/kill -SIGHUP [0-9]*, \
    /bin/rm -rf /config/moot-server/*, \
    /usr/sbin/service moot-server start, \
    /usr/sbin/service moot-server stop, \
    /usr/sbin/service nsx-ccp start, \
    /usr/sbin/service nsx-ccp stop, \
    /usr/bin/tcpdump, \
    /opt/vmware/nsx-cli/bin/scripts/termtcpdump, \
    /opt/vmware/nsx-edge/sbin/edge-ping, \
    /opt/vmware/nsx-edge/sbin/edge-ping6, \
    /opt/vmware/nsx-edge/sbin/edge-tracert, \
    /opt/vmware/nsx-edge/sbin/edge-tracert6, \
    /usr/sbin/traceroute, \
    /opt/vmware/nsx-cli/bin/scripts/dnsforwardercli, \
    /opt/vmware/nsx-cli/bin/scripts/log_cleaner.py, \
    /bin/netstat -natp -W, \
    /bin/ip netns exec plr_sr /opt/vmware/nsx-cli/bin/scripts/dnsforwardercli *,\
    /bin/ip netns exec nsx /opt/vmware/nsx-agent/bin/support_save.py, \
    /bin/ip netns exec nsx /sbin/ifconfig -a, \
    /bin/ip netns exec nsx /bin/netstat -nae, \
    /bin/ip netns exec tlr_sr curl http\://127.0.0.1\:9001/nsx/*, \
    /bin/cat /opt/vmware/etc/bootstrap-config, \
    /opt/vmware/nsx-cli/bin/scripts/frrcfg *,\
    /opt/vmware/upgrade-coordinator-tomcat/bin/call_uc_rollback, \
    /opt/vmware/nsx-keymanager/backup_restore.py -f * -b -p *, \
    /opt/vmware/nsx-keymanager/backup_restore.py -f * -r -p *, \
    /opt/vmware/nsx-edge/bin/config.py --corelist *, \
    /opt/vmware/nsx-edge/bin/config.py --hugepage reset, \
    /opt/vmware/nsx-edge/bin/config.py --hugepage auto, \
    /opt/vmware/nsx-edge/bin/config.py --hugepage [0-9]*, \
    /opt/vmware/nsx-edge/bin/config.py --packet-queue-limit *, \
    /opt/vmware/nsx-edge/bin/config.py --flow-cache-size *, \
    /opt/vmware/nsx-edge/bin/config.py --stats-thread-sleep-interval *, \
    /opt/vmware/nsx-edge/bin/config.py --disable_sc, \
    /opt/vmware/nsx-edge/bin/config.py --enable_sc, \
    /opt/vmware/nsx-edge/bin/config.py --crypto-enable-qat *, \
    /opt/vmware/nsx-edge/bin/config.py --nic_list *, \
    /opt/vmware/nsx-edge/bin/rss_hash.py *, \
    /usr/bin/docker images *, \
    /usr/bin/docker inspect *, \
    /bin/cp /opt/vmware/proxy-tomcat/conf/server.xml.orig /opt/vmware/proxy-tomcat/conf/server.xml, \
    /opt/vmware/nsx-netopa/bin/sha-appctl -c *, \
    /opt/vmware/nsx-cli/bin/scripts/showlog /var/log/* -[czft]

Cmnd_Alias  READNSXCLITOOLS = /opt/vmware/nsx-cli/bin/scripts/gen_support_bundle, \
    /opt/vmware/nsx-cli/bin/scripts/move_tmpfile_to_filestore, \
    /opt/vmware/nsx-cli/bin/scripts/backup_restore.sh, \
    /usr/bin/vtysh -c *, \
    /opt/vmware/nsx-cli/bin/scripts/start_nsx_services, \
    /opt/vmware/nsx-edge/bin/dns/dns_fdr-cli.py, \
    /opt/vmware/nsx-edge/bin/lb-perf-config.py, \
    /usr/bin/lstopo --no-caches, \
    /usr/bin/hugeadm --page-sizes-all, \
    /usr/bin/hugeadm --pool-list, \
    /opt/vmware/nsx-cli/bin/scripts/frrcfg *,\
    /bin/ip netns exec plr_sr /opt/vmware/nsx-cli/bin/scripts/dnsforwardercli *,\
    /opt/vmware/upgrade-coordinator-tomcat/bin/call_uc_rollback, \
    /opt/vmware/upgrade-coordinator-tomcat/bin/call_host_rollback, \
    /opt/vmware/upgrade-coordinator-tomcat/bin/call_host_rollback_display, \
    /opt/vmware/upgrade-coordinator-tomcat/bin/host_rollback.py, \
    /opt/vmware/upgrade-coordinator-tomcat/bin/host_rollback_display.py, \
    /opt/vmware/nsx-upgrade-agent/upgrade_bundle_helper.py, \
    /opt/vmware/node-rollback/bin/rollback_helper.py, \
    /opt/vmware/nsx-edge/bin/frr_cli_helper.py *,\
    /opt/vmware/nsx-edge/bin/perfall.py --interval [0-9], \
    /opt/vmware/nsx-edge/bin/perfall.py --interval [0-9][0-9], \
    /opt/vmware/nsx-edge/bin/config.py --crypto-show-qat, \
    /opt/vmware/nsx-edge/bin/pci_util.py --show-devs, \
    /usr/sbin/virt-what, \
    ! /usr/sbin/virt-what *--t*, \
    /bin/grep -i apparmor /var/log/audit/audit.log*, \
    /usr/bin/test -f /var/log/audit/audit.log*, \
    /usr/bin/ntpq -p, \
    /usr/bin/tail -F /var/log/*, \
    /usr/bin/vtysh -c, \
    /usr/bin/docker images *, \
    /usr/bin/docker inspect *, \
    /bin/passwd -S *, \
    /opt/vmware/nsx-netopa/bin/sha-appctl -c *

%nsxcli  ALL= NOPASSWD: READNSXCLITOOLS

%admin  ALL= NOPASSWD: ADMINNSXCLITOOLS
