Configuring Elevated Access (Sudo)
AppViewX requires sudo access to install Kubernetes and its dependencies. The installation user must NOT be root but must have sudo privileges.
Granular Sudo Commands Required
The table below lists all commands that the AppViewX installer executes with sudo. Add these to the sudoers file to restrict sudo access to only what is required.
| S/No. | Command | S.No. | Command |
|---|---|---|---|
| 1 | /usr/bin/cp | 2 | /usr/bin/mv |
| 3 | /usr/bin/rm | 4 | /usr/bin/mkdir |
| 5 | /usr/bin/chmod | 6 | /usr/bin/chown |
| 7 | /usr/bin/sed | 8 | /usr/bin/tee |
| 9 | /usr/bin/touch | 10 | /usr/bin/ln |
| 11 | /usr/bin/systemctl | 12 | /usr/bin/journalctl |
| 13 | /usr/bin/timedatectl | 14 | /usr/bin/grep |
| 15 | /usr/bin/cat | 16 | /usr/bin/whoami |
| 17 | /usr/bin/true | 18 | /usr/bin/sleep |
| 19 | /usr/bin/pkill | 20 | /usr/bin/tar |
| 21 | /usr/sbin/hwclock | 22 | /usr/sbin/modprobe |
| 23 | /usr/sbin/swapoff | 24 | /usr/sbin/setenforce |
| 25 | /usr/sbin/sysctl | 26 | /usr/bin/mount |
| 27 | /usr/bin/umount | 28 | /usr/sbin/ifconfig |
| 29 | /usr/sbin/ip | 30 | /usr/sbin/rmmod |
| 31 | /usr/sbin/firewall-cmd | 32 | /usr/sbin/tcpdump |
| 33 | /usr/bin/nc | 34 | /usr/bin/netstat |
| 35 | /usr/bin/kubeadm | 36 | /usr/bin/crictl |
| 37 | /usr/bin/calicoctl | 38 | /usr/bin/istioctl |
| 39 | /usr/bin/apt | 40 | /usr/bin/apt-get |
| 41 | /usr/bin/yum | 42 | /usr/bin/dpkg |
| 43 | /usr/bin/rpm | 44 | /usr/bin/openssl |
| 45 | /usr/bin/fips-mode-setup | 46 | /usr/bin/update-crypto-policies |
| 47 | <ABSOLUTE PATH>/k8s-kms-plugin/k8s-kms-plugin | 48 | /bin/bash |
| 49 | /bin/sh | 50 | /usr/bin/vi |
| 51 | <APPVIEWX INSTALLED PATH>/prereq-temp/validation |
Required Directory Access
In addition to commands, the sudo user must have read/write/execute access to the following directories:
| Directory | Required Access |
|---|---|
| /etc/ | Read / Write |
| /var/ | Read / Write |
| /usr/ | Read / Write |
Passwordless Sudo (Key-Based Installation)
For key-based (PEM) authentication without password prompts, configure passwordless sudo. As root, add to /etc/sudoers on all nodes:
<USERNAME> ALL=(ALL) NOPASSWD:ALL
# Verify sudoers syntax before saving:
sudo visudo -c
Note: NO PASSWD: ALL access is required only during
installation, maintenance activities, troubleshooting, and log collection.
Creating a New Sudo User
| Step | Ubuntu | RHEL / Rocky / Oracle |
|---|---|---|
| Create user | adduser <USERNAME> | useradd <USERNAME> |
| Set password | passwd <USERNAME> | passwd <USERNAME> |
| Add to sudo group | usermod -aG sudo <USERNAME> | usermod -aG wheel <USERNAME> |
| Verify | sudo ls -la /root | sudo ls -la /root |
Network Subnet Configuration
Configure in appviewx.conf before installation:
| Parameter | Requirement |
|---|---|
| SERVICE SUBNET | Must NOT conflict with any node IPs or existing network subnets. |
| POD SUBNET | Must NOT conflict with any node IPs or existing network subnets. |
