Skip to main content

runspec-linux-root

Linux admin tools that need root, as runspec runnables:

Tool What it does Autonomy
list-upgrades List packages with an available upgrade (refreshes the index) autonomous
upgrade-packages Refresh the index and upgrade every package confirm
install-package Install packages by name confirm
remove-package Remove packages (--purge for config files too) confirm
autoremove-packages Remove packages nothing depends on (--dry-run to preview) confirm
set-sysctl Set a kernel parameter, optionally persisted under /etc/sysctl.d confirm
reboot-host Reboot, optionally after a delay confirm
enable-passwordless-sudo One-time bootstrap: a validated /etc/sudoers.d drop-in confirm

They work across apt, dnf, yum, zypper and pacman. The logic lives in runspec-linux-core. The everyday tools that never need root are in runspec-linux.

Install into a root-owned venv

Every tool here declares run_as = "root": root runs this code. So install it into a venv only root can change. A venv owned by a service account would let that account edit code root later runs.

sudo python3 -m venv /opt/venvs/admin
sudo /opt/venvs/admin/bin/pip install runspec-linux-root

Who can run them

sudoers decides. An admin runs a tool with sudo:

sudo /opt/venvs/admin/bin/upgrade-packages

runspec checks the process really is root (enforce_run_as) and refuses otherwise, naming the account to sudo -u to.

From runspec-console or the MCP gateway, the tool is run with sudo -n, which never prompts for a password, so the admin needs a passwordless sudo rule. enable-passwordless-sudo installs one:

  • --scope scoped allows only this venv's tools, run directly (sudo /opt/venvs/admin/bin/<tool> from a shell or cron). It does not cover the console or the gateway, which pass variables to the tool through a sh prelude so that secrets never go on a command line; sudo then sees sh, not the tool.
  • --scope all grants NOPASSWD: ALL, which the console and the gateway need.

Metadata

Release files for runspec-linux-root 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for runspec-linux-root 0.1.0
File Size Uploaded
runspec_linux_root-0.1.0.tar.gz 5.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for runspec-linux-root 0.1.0
File Interpreter ABI Platform
runspec_linux_root-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 12.7 kB

Release files / runspec_linux_root-0.1.0.tar.gz

Download URL runspec_linux_root-0.1.0.tar.gz
Size 5.9 kB
Tags Source
SHA-256 checksum
How to use checksums
35862fc1b70b132e86db1102666a782d45904a89e2fd604be2bb825c29455dff
BLAKE2b-256 checksum
How to use checksums
3d26aed93ae71055ea311be86abf48e175414c17106586ecdb98401e62601a76
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / runspec_linux_root-0.1.0-py3-none-any.whl

Download URL runspec_linux_root-0.1.0-py3-none-any.whl
Size 6.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
30bad70171afcdd2de1a05dc68cfa604291f2c1259395d01d25e5cfe55cfe136
BLAKE2b-256 checksum
How to use checksums
a12e504d5c840ca40887149182e1f7858da5afdc3d54a2ebd2e9e05dee0b645c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page