Closed Vince0789 closed 17 hours ago
Thank you for your contribution @Vince0789 I'll take your improvement into consideration and rewrite the documentation.
Also thank you for being so helpful!
@Vince0789 Sorry to ping you again. Could you please review the PR when you have a moment and let me know if it needs any enhancements?
Link to the rewritten branch: https://github.com/itsneufox/installation_openmp_ubuntu/tree/Rewrite
Thanks a bunch!
Follow the principle of least privilege. A user or service account should not get more privileges than it needs to do its job. Adding it to the sudo'ers group is a very bad idea as it essentially makes the account an admin on the system, when it does not need that privilege at all.
A few considerations of mine:
svc-omp-server
. You could pass the-M
flag to skip the creation of a home directory.usermod -L svc-omp-server
/opt
, e.g./opt/omp-server
, which is the preferred place for third party apps and packageschgrp svc-omp-server /opt/omp-server
chmod g+s /opt/omp-server
chmod o-rwx /opt/omp-server
wget
etc. in there to download the server files. The group permissions should be automatically inherited by all files and folder because of the GID bit. This means the service account can access and run them. Any new files created in there by anyone should also automatically inherit the correct group.Any other user that you may want to give access to the directory, you can add into the svc-omp-server group.