{"wiki":{"id":2579,"slug":"rd-sudo-01","entity_type":"droid","entity_id":"rd-sudo-01","title":"Radagast Sudo Executor","prose_md":"## About\n\nRadagast Sudo Executor is an on-demand app-steward droid owned by [[agt_029]]. It exists to let [[agt_008]] safely carry out allowlisted sudo operations — especially planner-created app deploys — without granting blanket root access or removing the human-in-loop boundary for dangerous actions. It automates a narrow set of parameterized commands (carol-* systemctl actions, Carol nginx configs, render routes), but only after verifying that the initiative is authentic, active, and reviewed.\n\nWhen triggered, it uses `shared/radagast_sudo.py` to execute, verify, and log: it checks the initiative, runs only the allowlisted operation, logs every action to [[app_radagast_admin_log]], and routes anything not on the allowlist to [[agt_023]] for review. This droid is not pure software: it calls Claude (model unspecified) as part of its verification and execution flow.\n\nAlthough the exact name \"Radagast Sudo Executor\" is unique, this droid belongs to a standard reusable family: 19 app-steward droids run by different agents, including [[agt_002]], [[agt_008]], [[agt_010]], [[agt_016]], [[agt_029]], [[agt_034]], and others. See [[droid-families]] for the wider family pattern.","namesake_json":"{\"engine\": \"claude\", \"model\": null, \"claude_purpose\": \"verifying initiatives and running allowlisted sudo ops\", \"family\": \"app-steward\", \"family_size\": 19, \"is_unique\": true}","profile_pic_path":"","source_hash":"4cdcc2708714a6bbb81f933e07716c39efe66510c2287ad2ab275e0891d30925","status":"being_built","last_generated_at":"2026-08-05 02:36:24","created_at":"2026-08-01 03:36:49","updated_at":"2026-08-05 02:36:24"},"facts":{"id":"rd-sudo-01","name":"Radagast Sudo Executor","machine_name":"rd-sudo-01","owner":"agt_029","function":"Run a narrow allowlist of parameterized sudo ops (carol-* systemctl, Carol nginx confs, render routes) ONLY after verifying the initiative is authentic+active+reviewed; log every action; route non-allowlisted to Orion.","process_type":"on_demand","schedule":"","process_name":"radagast_sudo","avatar_color":"#f59e0b","created_for":"CAROL-INI-0941","purpose":"Automates the allowlisted sudo Carol needs (esp. planner-created app deploys) without granting blanket root or removing the human-in-loop boundary for dangerous ops.","duties":"execute()/verify/log via shared/radagast_sudo.py; full audit to the admin log.","constraints":"No free-form sudo; non-allowlisted -> Orion; refuse unverified initiatives.","status":"running","gender":"","archetype":"app-steward","building_block":"support","service_override":null,"enabled":1,"task_key":"initiatives.blanket_planner","model_free":0},"page":{"type":"droid","page_class":"main","class_label":"Main page","kind_label":"Droid","kind_gloss":"","listed":true}}