hop3-rootd
Privileged-operations agent for Hop3. Runs as root; exposes a narrow control-plane API to hop3-server (running unprivileged as the hop3 user) over a Unix domain socket.
See notes/adrs/041-privileged-operations-agent.md for the design rationale and notes/adrs/040-network-firewall-and-port-exposure.md for the firewall integration that motivated v1's op set.
What this is
hop3-rootd is the kernel-boundary executor for Hop3's runtime privileged actions. The unprivileged hop3-server reaches it via a Unix socket; rootd validates each request structurally, applies the privileged action (nftables mutation, nginx reload, etc.), and returns a typed result.
In v1 the operations are:
firewall.add_rule,firewall.remove_rule,firewall.list_rules— manage rules in a dedicatedinet hop3nftables table.nginx.reload,nginx.validate_config— wrap the privileged nginx commands previously granted tohop3-servervia/etc/sudoers.d/hop3(now retired).daemon.health,daemon.handshake— introspection.
What this is not
- A policy enforcement layer. SO_PEERCRED admits the
hop3user; structural validation rejects malformed requests. There is no per-op authorization, no policy file. Operator-level "did you mean this?" prompts live inhop3 deploy, not in rootd. - A general-purpose privileged-shell daemon. Rootd never accepts shell strings; every operation is a typed intent with a fixed argument schema.
Deployment
hop3-rootd ships as a stdlib-only Python package and is installed by hop3-installer alongside hop3-server. It runs as a hardened systemd unit (full ProtectX suite, CapabilityBoundingSet=CAP_NET_ADMIN, syscall filter, resource limits). The socket is at /run/hop3-rootd/socket, mode 0660, group hop3.
Development
# Run unit tests (no privileges needed)
pytest tests/a_unit/ -v
# Run integration tests (requires root + nftables)
sudo pytest tests/b_integration/ -v
# Lint
ruff check src tests
ruff format src tests
License
Apache-2.0 — Copyright (c) 2026, Abilian SAS
Metadata
Release files for hop3-rootd 0.7.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| hop3_rootd-0.7.5.tar.gz | 66.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| hop3_rootd-0.7.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 150.6 kB
Release files / hop3_rootd-0.7.5.tar.gz
| Download URL | hop3_rootd-0.7.5.tar.gz |
|---|---|
| Size | 66.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
51bb28458101a28f8afa706d2d4b848c13ea1d07ecb448dd9783e1c2045175c6
|
|
BLAKE2b-256 checksum How to use checksums |
661af9dcc61d366920d9ef1767777bd4f21823a4550f2b51baac0fccc64225a5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.13
|
Release files / hop3_rootd-0.7.5-py3-none-any.whl
| Download URL | hop3_rootd-0.7.5-py3-none-any.whl |
|---|---|
| Size | 84.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9bea1de3c3c4325661070a05973eb00614eb7e5de162252b83c56e1f16ee1eb3
|
|
BLAKE2b-256 checksum How to use checksums |
ac9e62264bbcac2a7018c3a0f35fba24d3a2221f863050f1d1d7e7c18ddf0b7e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.13
|