LOGBOOK

HELP

Quiz Entry - updated: 2026.10.01

Prometheus is installed under its own account with useradd -s /sbin/nologin --system -g prometheus prometheus. What does each part do, and why?

It creates a system user prometheus in group prometheus that cannot log in interactively. The service runs with least privilege, and nobody can get a shell as that user.

  • --system creates a system account: UID below 1000, no password ageing, and by default no home directory. It marks the account as belonging to a service, not a person. (groupadd --system prometheus beforehand creates the matching system group, GID below 1000.)
  • -g prometheus makes prometheus the user's primary group.
  • -s /sbin/nologin sets the login shell to a program that just prints "This account is currently not available" and exits. So even with a password, SSH or su would not yield a shell.
  • prometheus is the user name.

Why bother: if Prometheus is compromised, the attacker gets only the rights of an unprivileged account that owns /etc/prometheus and /var/lib/prometheus, not root. The chown -R prometheus:prometheus steps afterwards give exactly that account access to its config and data directories.

Go deeper:

From Quiz: ITIA / Monitoring Lab: Prometheus and Grafana | Updated: Oct 01, 2026