sudo and sudoers

sudo, visudo and the sudoers File

sudo runs one command as another user after checking a policy and asking for your own password. There is no shared root password, every command is logged against a named person, and a grant can be narrowed to specific commands. The policy is /etc/sudoers plus /etc/sudoers.d/*. A rule such as deploy ALL=(root) NOPASSWD: /usr/bin/systemctl reload php8.5-fpm reads left to right: this user (or %group), on this host (almost always ALL), may run as this user ((user:group) to set both), with optional tags, these commands, each an absolute path. Debian 319 and Ubuntu 225 grant administration with %sudo ALL=(ALL:ALL) ALL; Red Hat, Fedora 1,480 , Rocky and AlmaLinux 7,122 use %wheel ALL=(ALL) ALL. Neither group name is special to sudo itself.

Aliases, Defaults and grants in a sudoers fileShell
Cmnd_Alias WEBCTL = /usr/bin/systemctl restart apache2, \
                    /usr/bin/systemctl reload apache2
User_Alias WEBOPS = alice, bob
Defaults        env_reset, timestamp_timeout=15
Defaults        secure_path="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
root            ALL=(ALL:ALL) ALL
%sudo           ALL=(ALL:ALL) ALL
WEBOPS          ALL=(root) WEBCTL

env_reset gives the command a fresh minimal environment, so a poisoned LD_PRELOAD cannot ride along (sudo-rs cannot turn it off). secure_path replaces PATH, so a systemctl planted in your PATH never runs. timestamp_timeout is how many minutes a password is remembered per terminal (15 by default; sudo -k forgets it). Ubuntu's /etc/sudoers ends with @includedir /etc/sudoers.d; the older #includedir is not a comment.

Always edit with visudo, which locks the file and parses your edit before installing it. A broken sudoers means nobody can use sudo, and with root locked that is a rescue-console job. Stage changes in a scratch file and check them with visudo -cf.

Checking sudo policy before it goes liveShell
sudo --version
sudo visudo -c                      # parse the live policy
sudo visudo -cf policy.sudoers      # the listing above, in a scratch file
sudo visudo -cf bad.sudoers         # one letter missing from NOPASSWD
Output
sudo-rs 0.2.13-0ubuntu1
/etc/sudoers: parsed OK
policy.sudoers: parsed OK
bad.sudoers:1:28: syntax error: expected host name
deploy ALL=(root) NOPASWD: /usr/bin/systemctl reload php8.5-fpm
                           ^
visudo: invalid sudoers file