Skip to main content

hop3-rootd

Privileged-operations agent for Hop3. Runs as root; exposes a narrow control-plane API to hop3-server (running unprivileged as the hop3 user) over a Unix domain socket.

See notes/adrs/041-privileged-operations-agent.md for the design rationale and notes/adrs/040-network-firewall-and-port-exposure.md for the firewall integration that motivated v1's op set.

What this is

hop3-rootd is the kernel-boundary executor for Hop3's runtime privileged actions. The unprivileged hop3-server reaches it via a Unix socket; rootd validates each request structurally, applies the privileged action (nftables mutation, nginx reload, etc.), and returns a typed result.

In v1 the operations are:

  • firewall.add_rule, firewall.remove_rule, firewall.list_rules — manage rules in a dedicated inet hop3 nftables table.
  • nginx.reload, nginx.validate_config — wrap the privileged nginx commands previously granted to hop3-server via /etc/sudoers.d/hop3 (now retired).
  • daemon.health, daemon.handshake — introspection.

What this is not

  • A policy enforcement layer. SO_PEERCRED admits the hop3 user; structural validation rejects malformed requests. There is no per-op authorization, no policy file. Operator-level "did you mean this?" prompts live in hop3 deploy, not in rootd.
  • A general-purpose privileged-shell daemon. Rootd never accepts shell strings; every operation is a typed intent with a fixed argument schema.

Deployment

hop3-rootd ships as a stdlib-only Python package and is installed by hop3-installer alongside hop3-server. It runs as a hardened systemd unit (full ProtectX suite, CapabilityBoundingSet=CAP_NET_ADMIN, syscall filter, resource limits). The socket is at /run/hop3-rootd/socket, mode 0660, group hop3.

Development

# Run unit tests (no privileges needed)
pytest tests/a_unit/ -v

# Run integration tests (requires root + nftables)
sudo pytest tests/b_integration/ -v

# Lint
ruff check src tests
ruff format src tests

License

Apache-2.0 — Copyright (c) 2026, Abilian SAS

Metadata

Release files for hop3-rootd 0.7.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hop3-rootd 0.7.2
File Size Uploaded
hop3_rootd-0.7.2.tar.gz 63.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hop3-rootd 0.7.2
File Interpreter ABI Platform
hop3_rootd-0.7.2-py3-none-any.whl Python 3 none any Details

Total release size: 144.1 kB

Release files / hop3_rootd-0.7.2.tar.gz

Download URL hop3_rootd-0.7.2.tar.gz
Size 63.4 kB
Tags Source
SHA-256 checksum
How to use checksums
fa8d74df56229dfb25b2b814f393fdc661560052fbc7c88b07b3b72f6491d25e
BLAKE2b-256 checksum
How to use checksums
43d34475d1f0ebfaa263aad2088a6c7d23916ab81b15899b54f4dd866baf0bfe
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.13

Release files / hop3_rootd-0.7.2-py3-none-any.whl

Download URL hop3_rootd-0.7.2-py3-none-any.whl
Size 80.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cba37089d393aea248fced00379a276dfa67544f0bd437d7f6476d389a080afb
BLAKE2b-256 checksum
How to use checksums
9688cdf87aa0a9f6fb04818308bcb240fcf176d60bb6f2d8787437cccea7bd2f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.13

Release history Release notifications | RSS feed

0.7.5

2 release files

0.7.4

2 release files

0.7.3

2 release files

This release

0.7.2 This release

2 release files

0.7.1

2 release files

0.6.2

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page