Configuring Elevated Access (Sudo)

AppViewX requires sudo access to install Kubernetes and its dependencies. The installation user must NOT be root but must have sudo privileges.

Granular Sudo Commands Required

The table below lists all commands that the AppViewX installer executes with sudo. Add these to the sudoers file to restrict sudo access to only what is required.

S/No. Command S.No. Command
1 /usr/bin/cp 2 /usr/bin/mv
3 /usr/bin/rm 4 /usr/bin/mkdir
5 /usr/bin/chmod 6 /usr/bin/chown
7 /usr/bin/sed 8 /usr/bin/tee
9 /usr/bin/touch 10 /usr/bin/ln
11 /usr/bin/systemctl 12 /usr/bin/journalctl
13 /usr/bin/timedatectl 14 /usr/bin/grep
15 /usr/bin/cat 16 /usr/bin/whoami
17 /usr/bin/true 18 /usr/bin/sleep
19 /usr/bin/pkill 20 /usr/bin/tar
21 /usr/sbin/hwclock 22 /usr/sbin/modprobe
23 /usr/sbin/swapoff 24 /usr/sbin/setenforce
25 /usr/sbin/sysctl 26 /usr/bin/mount
27 /usr/bin/umount 28 /usr/sbin/ifconfig
29 /usr/sbin/ip 30 /usr/sbin/rmmod
31 /usr/sbin/firewall-cmd 32 /usr/sbin/tcpdump
33 /usr/bin/nc 34 /usr/bin/netstat
35 /usr/bin/kubeadm 36 /usr/bin/crictl
37 /usr/bin/calicoctl 38 /usr/bin/istioctl
39 /usr/bin/apt 40 /usr/bin/apt-get
41 /usr/bin/yum 42 /usr/bin/dpkg
43 /usr/bin/rpm 44 /usr/bin/openssl
45 /usr/bin/fips-mode-setup 46 /usr/bin/update-crypto-policies
47 <ABSOLUTE PATH>/k8s-kms-plugin/k8s-kms-plugin 48 /bin/bash
49 /bin/sh 50 /usr/bin/vi
51 <APPVIEWX INSTALLED PATH>/prereq-temp/validation

Required Directory Access

In addition to commands, the sudo user must have read/write/execute access to the following directories:

Directory Required Access
/etc/ Read / Write
/var/ Read / Write
/usr/ Read / Write

Passwordless Sudo (Key-Based Installation)

For key-based (PEM) authentication without password prompts, configure passwordless sudo. As root, add to /etc/sudoers on all nodes:

<USERNAME> ALL=(ALL) NOPASSWD:ALL
# Verify sudoers syntax before saving:
sudo visudo -c
Note: NO PASSWD: ALL access is required only during installation, maintenance activities, troubleshooting, and log collection.

Creating a New Sudo User

Step Ubuntu RHEL / Rocky / Oracle
Create user adduser <USERNAME> useradd <USERNAME>
Set password passwd <USERNAME> passwd <USERNAME>
Add to sudo group usermod -aG sudo <USERNAME> usermod -aG wheel <USERNAME>
Verify sudo ls -la /root sudo ls -la /root

Network Subnet Configuration

Configure in appviewx.conf before installation:

Parameter Requirement
SERVICE SUBNET Must NOT conflict with any node IPs or existing network subnets.
POD SUBNET Must NOT conflict with any node IPs or existing network subnets.