# Always allow root logins. +:root:ALL # Allow icinga user for monitoring via SSH. +:${icinga_local_user}:ALL $(if [ -n "${acmeproxy_client_group:-}" ]; then echo "+:(${acmeproxy_client_group}):ALL" fi if [ -n "${login_access_groups:-}" ] || [ -n "${login_access_users:-}" ]; then printf -- '-:ALL EXCEPT ' if [ -n "${login_access_groups:-}" ]; then printf '(%s) ' ${login_access_groups} fi if [ -n "${login_access_users:-}" ]; then printf '%s ' ${login_access_users} fi printf ':ALL\n' fi)