Skip to main content

runspec-linux-root

Linux admin tools that need root, as runspec runnables:

Tool What it does Autonomy
list-upgrades List packages with an available upgrade (refreshes the index) autonomous
upgrade-packages Refresh the index and upgrade every package confirm
install-package Install packages by name confirm
remove-package Remove packages (--purge for config files too) confirm
autoremove-packages Remove packages nothing depends on (--dry-run to preview) confirm
set-sysctl Set a kernel parameter, optionally persisted under /etc/sysctl.d confirm
reboot-host Reboot, optionally after a delay confirm
enable-passwordless-sudo One-time bootstrap: a validated /etc/sudoers.d drop-in confirm

They work across apt, dnf, yum, zypper and pacman. The logic lives in runspec-linux-core. The everyday tools that never need root are in runspec-linux.

Install into a root-owned venv

Every tool here declares run_as = "root": root runs this code. So install it into a venv only root can change. A venv owned by a service account would let that account edit code root later runs.

sudo python3 -m venv /opt/venvs/admin
sudo /opt/venvs/admin/bin/pip install runspec-linux-root

Who can run them

sudoers decides. An admin runs a tool with sudo:

sudo /opt/venvs/admin/bin/upgrade-packages

runspec checks the process really is root (enforce_run_as) and refuses otherwise, naming the account to sudo -u to.

From runspec-console or the MCP gateway, the tool is run with sudo -n, which never prompts for a password, so the admin needs a passwordless sudo rule. enable-passwordless-sudo installs one:

  • --scope scoped allows only the programs in this venv's bin/. That covers direct runs (sudo /opt/venvs/admin/bin/<tool> from a shell or cron) and, with runspec-console / runspec-mcp built on runspec ≥ 0.70.0, console and gateway runs too. Those pass variables to the tool on stdin through a small prelude that runs on the venv's own bin/python, which the scoped rule covers. (Before runspec 0.70.0 the prelude ran on sh, which the scoped rule doesn't cover, so console runs that carried variables needed --scope all.)
  • --scope all grants NOPASSWD: ALL.

Metadata

Release files for runspec-linux-root 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for runspec-linux-root 0.1.1
File Size Uploaded
runspec_linux_root-0.1.1.tar.gz 6.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for runspec-linux-root 0.1.1
File Interpreter ABI Platform
runspec_linux_root-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 13.0 kB

Release files / runspec_linux_root-0.1.1.tar.gz

Download URL runspec_linux_root-0.1.1.tar.gz
Size 6.1 kB
Tags Source
SHA-256 checksum
How to use checksums
6257cb47ecf4d4b6e26bf3fba40ee62b64ec04b01b77f56c4722e4b7ea654569
BLAKE2b-256 checksum
How to use checksums
af7a4b28c9a90ccb22717e88c11860e862e9e16e92488150e41edcb25755e4fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / runspec_linux_root-0.1.1-py3-none-any.whl

Download URL runspec_linux_root-0.1.1-py3-none-any.whl
Size 6.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
70f0887a5c3331bdb982210785a35a75e8c2f7ef6a23f179d832f6bcb79b27d3
BLAKE2b-256 checksum
How to use checksums
3ba36615feb6b78480ff0a3a7a886b4bdfce3c5a6119523984e350cd54898f55
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page