Permissions lab
Goal
Simulate a shared workspace where developers can read logs but only operators can rotate them.
Tasks
- Create
logs/andarchive/directories. - Assign ownership to
opsgroup. - Grant read-only access to
devs. - Verify access with a test user.
Expected outcome
devs can read logs but cannot delete or overwrite them.