Quiz Entry - updated: 2026.10.01
Prometheus is installed under its own account with useradd -s /sbin/nologin --system -g prometheus prometheus. What does each part do, and why?
It creates a system user prometheus in group prometheus that cannot log in interactively. The service runs with least privilege, and nobody can get a shell as that user.
--systemcreates a system account: UID below 1000, no password ageing, and by default no home directory. It marks the account as belonging to a service, not a person. (groupadd --system prometheusbeforehand creates the matching system group, GID below 1000.)-g prometheusmakesprometheusthe user's primary group.-s /sbin/nologinsets the login shell to a program that just prints "This account is currently not available" and exits. So even with a password, SSH orsuwould not yield a shell.prometheusis the user name.
Why bother: if Prometheus is compromised, the attacker gets only the rights of an unprivileged account that owns /etc/prometheus and /var/lib/prometheus, not root. The chown -R prometheus:prometheus steps afterwards give exactly that account access to its config and data directories.
Go deeper:
useradd(8) — Linux manual page — --system, -g, -s and what a system account gets by default.
nologin(8) — Linux manual page — what the nologin shell does when someone tries to log in.