Always edit sudo rules with visudo (or visudo -f /etc/sudoers.d/<name>), which checks syntax before saving. A syntax error in a sudoers file can lock you out of sudo entirely.
Passwordless sudo for one user¶
# /etc/sudoers.d/00-alice (mode 0440)
alice ALL=(ALL) NOPASSWD: ALL
sudo visudo -f /etc/sudoers.d/00-alice
sudo chmod 0440 /etc/sudoers.d/00-alice
Full passwordless root convenience removes a safeguard: anything running as that user can become root. Restrict it to commands you need on shared or exposed machines.
Allow only specific commands¶
alice ALL = NOPASSWD: /bin/systemctl start myservice.service, /bin/systemctl stop myservice.service, /bin/systemctl restart myservice.service, /bin/systemctl status myservice.service
Use full paths to the binary, and avoid allowing commands that can spawn shells (editors, less, find, and scripting interpreters).
Let a user or group reboot and shut down¶
sudo groupadd shutdown
sudo usermod -aG shutdown alice
# visudo -f /etc/sudoers.d/shutdown
%shutdown ALL=(root) NOPASSWD: /sbin/reboot, /sbin/halt, /sbin/shutdown
Fix a broken sudo¶
If a bad sudoers file blocks sudo, use pkexec (polkit) or a root console or recovery boot:
pkexec visudo
pkexec rm /etc/sudoers.d/00-alice
pkexec [--user username] PROGRAM [ARGUMENTS...] executes a program as another user (root by default) after polkit authorisation.
Check what you can do¶
sudo -l # list your allowed commands
sudo -k # forget cached credentials