Skip to main content

hop3-rootd

Privileged-operations agent for Hop3. Runs as root; exposes a narrow control-plane API to hop3-server (running unprivileged as the hop3 user) over a Unix domain socket.

See notes/adrs/041-privileged-operations-agent.md for the design rationale and notes/adrs/040-network-firewall-and-port-exposure.md for the firewall integration that motivated v1's op set.

What this is

hop3-rootd is the kernel-boundary executor for Hop3's runtime privileged actions. The unprivileged hop3-server reaches it via a Unix socket; rootd validates each request structurally, applies the privileged action (nftables mutation, nginx reload, etc.), and returns a typed result.

In v1 the operations are:

  • firewall.add_rule, firewall.remove_rule, firewall.list_rules — manage rules in a dedicated inet hop3 nftables table.
  • nginx.reload, nginx.validate_config — wrap the privileged nginx commands previously granted to hop3-server via /etc/sudoers.d/hop3 (now retired).
  • daemon.health, daemon.handshake — introspection.

What this is not

  • A policy enforcement layer. SO_PEERCRED admits the hop3 user; structural validation rejects malformed requests. There is no per-op authorization, no policy file. Operator-level "did you mean this?" prompts live in hop3 deploy, not in rootd.
  • A general-purpose privileged-shell daemon. Rootd never accepts shell strings; every operation is a typed intent with a fixed argument schema.

Deployment

hop3-rootd ships as a stdlib-only Python package and is installed by hop3-installer alongside hop3-server. It runs as a hardened systemd unit (full ProtectX suite, CapabilityBoundingSet=CAP_NET_ADMIN, syscall filter, resource limits). The socket is at /run/hop3-rootd/socket, mode 0660, group hop3.

Development

# Run unit tests (no privileges needed)
pytest tests/a_unit/ -v

# Run integration tests (requires root + nftables)
sudo pytest tests/b_integration/ -v

# Lint
ruff check src tests
ruff format src tests

License

Apache-2.0 — Copyright (c) 2026, Abilian SAS

Metadata

Release files for hop3-rootd 0.7.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hop3-rootd 0.7.3
File Size Uploaded
hop3_rootd-0.7.3.tar.gz 65.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hop3-rootd 0.7.3
File Interpreter ABI Platform
hop3_rootd-0.7.3-py3-none-any.whl Python 3 none any Details

Total release size: 148.7 kB

Release files / hop3_rootd-0.7.3.tar.gz

Download URL hop3_rootd-0.7.3.tar.gz
Size 65.3 kB
Tags Source
SHA-256 checksum
How to use checksums
d595e057a50e2b7cea842eab9af21c95d13f6359420a6255359bea702182b644
BLAKE2b-256 checksum
How to use checksums
9ba5a1c8facad6fde00e60f786b673175c7123aa3df11356cd995f85d54dde1e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.13

Release files / hop3_rootd-0.7.3-py3-none-any.whl

Download URL hop3_rootd-0.7.3-py3-none-any.whl
Size 83.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
59966047e6173847510ed8c3b9f55cb041386d5951e17429b8742c911ed9adaa
BLAKE2b-256 checksum
How to use checksums
d0867d258a2bc0311ff07b53b4dc422b64ca9982d686e789ede008face906b95
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.13

Release history Release notifications | RSS feed

0.7.5

2 release files

0.7.4

2 release files

This release

0.7.3 This release

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.6.2

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page