Note:
This topic has been translated from a Chinese forum by GPT and might contain errors.Original topic: tidb集群中的账号在安全审计中遇到的问题
The security audit of the customer’s project today raised the following requirements regarding the TiDB cluster accounts. Please refer to them together:
- The purpose of the tidb-installer account, and whether it can be deleted.
- The permissions of the tidb and tidb-installer accounts in the /etc/sudoers file are required to be rectified as follows:
tidb-installer ALL=(ALL) NOPASSWD: ALL
Defaults: tidb-installer !requiretty
tiup ALL=(ALL) NOPASSWD: ALL
Defaults: tiup !requiretty
tidb ALL=(ALL) NOPASSWD: ALL - However, the deployment of TiDB uses the tidb account, and it is required to change the password regularly in the future. It is unclear what impact this will have.