runspec-linux-root
Linux admin tools that need root, as runspec runnables:
| Tool | What it does | Autonomy |
|---|---|---|
list-upgrades |
List packages with an available upgrade (refreshes the index) | autonomous |
upgrade-packages |
Refresh the index and upgrade every package | confirm |
install-package |
Install packages by name | confirm |
remove-package |
Remove packages (--purge for config files too) |
confirm |
autoremove-packages |
Remove packages nothing depends on (--dry-run to preview) |
confirm |
set-sysctl |
Set a kernel parameter, optionally persisted under /etc/sysctl.d |
confirm |
reboot-host |
Reboot, optionally after a delay | confirm |
enable-passwordless-sudo |
One-time bootstrap: a validated /etc/sudoers.d drop-in |
confirm |
They work across apt, dnf, yum, zypper and pacman. The logic lives in
runspec-linux-core. The
everyday tools that never need root are in
runspec-linux.
Install into a root-owned venv
Every tool here declares run_as = "root": root runs this code. So install it
into a venv only root can change. A venv owned by a service account would
let that account edit code root later runs.
sudo python3 -m venv /opt/venvs/admin
sudo /opt/venvs/admin/bin/pip install runspec-linux-root
Who can run them
sudoers decides. An admin runs a tool with sudo:
sudo /opt/venvs/admin/bin/upgrade-packages
runspec checks the process really is root (enforce_run_as) and refuses
otherwise, naming the account to sudo -u to.
From runspec-console or the MCP gateway, the tool is run with sudo -n,
which never prompts for a password, so the admin needs a passwordless sudo rule.
enable-passwordless-sudo installs one:
--scope scopedallows only this venv's tools, run directly (sudo /opt/venvs/admin/bin/<tool>from a shell or cron). It does not cover the console or the gateway, which pass variables to the tool through ashprelude so that secrets never go on a command line; sudo then seessh, not the tool.--scope allgrantsNOPASSWD: ALL, which the console and the gateway need.
Metadata
Release files for runspec-linux-root 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| runspec_linux_root-0.1.0.tar.gz | 5.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| runspec_linux_root-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 12.7 kB
Release files / runspec_linux_root-0.1.0.tar.gz
| Download URL | runspec_linux_root-0.1.0.tar.gz |
|---|---|
| Size | 5.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
35862fc1b70b132e86db1102666a782d45904a89e2fd604be2bb825c29455dff
|
|
BLAKE2b-256 checksum How to use checksums |
3d26aed93ae71055ea311be86abf48e175414c17106586ecdb98401e62601a76
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / runspec_linux_root-0.1.0-py3-none-any.whl
| Download URL | runspec_linux_root-0.1.0-py3-none-any.whl |
|---|---|
| Size | 6.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
30bad70171afcdd2de1a05dc68cfa604291f2c1259395d01d25e5cfe55cfe136
|
|
BLAKE2b-256 checksum How to use checksums |
a12e504d5c840ca40887149182e1f7858da5afdc3d54a2ebd2e9e05dee0b645c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log