blob: a7ecf0f1b52a8660555c6f131f7ba2b87583fd20 [file] [edit]
# OS policy assignment that sets the /var/log/auth.log group to logaccess.
osPolicies:
- id: log-access-policy
mode: ENFORCEMENT
resourceGroups:
resources:
- id: grant-log-access
exec:
validate:
# Checks if the group is logaccess. If yes, exits with code 100. If no,
# exits with code 101 and proceeds to the `enforce` step.
script:
if stat -c '%G' /var/log/auth.log | grep -q 'logaccess'; then exit 100; else exit 101; fi
interpreter: SHELL
enforce:
# Changes the group to logaccess and exits with code 100.
script:
chgrp logaccess /var/log/auth.log && exit 100
instanceFilter:
inclusionLabels:
- labels:
vm: tutorial
rollout:
disruptionBudget:
fixed: 10
minWaitDuration: 30s