Run command as not-root

Hi everyone

At work, I have to run a command in an AWS instance. In that particular instance only exists the root user. The command should not be executed with root privileges (it executes mpirun, which is not recommended to run as sudo or the machine might break), so I was wondering if there is a way to block or disable the sudo privileges while the command is running. As mentioned, the only user existing there is root, so I suppose “sudo -u” is not an option.

Does anyone know how to do it? Thanks in advance!

@linux

  • Rustmilian
    link
    1
    edit-2
    1 year ago

    There’s a source that says something about using the AWS Systems Manager Session Manager by ““Configuring the necessary IAM permissions for your user or role to access the instance using Session Manager 1
    Open the AWS Systems Manager console, navigate to the “Session Manager” page, and select the instance you want to access
    Click on the “Start session” button to initiate the session with the instance.
    Once the session is established, you can run commands as the root user without the need for sudo””
    I’m unsure if this achieves exactly what you need though.

    • Nicolas RojasOP
      link
      fedilink
      11 year ago

      @Rustmilian Just did that and that is exactly what I needed, but in this case it didn’t work. In this page https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager-prerequisites.html they explain that what the manager does is creating another root account in the instance, and that new account is the one that can disable its own permissions. So, I ended up with the same problem of having to configure everything for the new user. However I’m done with the laziness and I’m gonna do it lol, everyone else pointed out that not having a regular user is a security issue and they are right. If I had configured the instance from the beginning with the SSM, I could have skipped all that work, but the reality is that I have to do it
      After I’m done configuring everything, I think I’ll set up the rest of the instances to work with the SSM so that I don’t have to go through all that again
      Thanks for the help!