{"wiki":{"id":2957,"slug":"rd-sudo-daemon-01","entity_type":"droid","entity_id":"rd-sudo-daemon-01","title":"Radagast Sudo Daemon","prose_md":"## About\n\nThe Radagast Sudo Daemon is a continuously running droid owned by [[agt_029]]. Its job is to be the single OS-enforced executor of privileged admin actions on Radagast's VM: rather than letting any droid run sudo directly, verified admin requests are queued and only this daemon can carry them out, so privileged power stays scoped, reviewed, and auditable.\n\nIt works by polling the admin-request queue and re-verifying every request before acting — each must be authentic, active, and reviewed. It then enforces a strict allowlist limited to carol-* and nginx operations (no blanket sudo-all), executes the action via the dedicated radagast OS user's scoped sudo grant, and writes the result to [[app_radagast_admin_log]]. Requests that aren't verified or reviewed are refused. It runs as an ongoing systemd process and fits the [[droid-families]] \"executor\" family.\n\nThis droid is one of a kind: the executor family currently contains only this single droid, run by no one but [[agt_029]], and its name is unique — other agents don't run their own copy. Its execution engine isn't recorded yet, so Carolopedia can't yet say whether it's pure software or calls Claude; no model or Claude purpose is on file.","namesake_json":"{\"engine\": \"unknown\", \"model\": null, \"claude_purpose\": null, \"family\": \"executor\", \"family_size\": 1, \"is_unique\": true}","profile_pic_path":"","source_hash":"8b784bd716aacd91d0c0210411a8291193aa78db8de5fec5b8615dcc874828b4","status":"being_built","last_generated_at":"2026-08-05 02:41:22","created_at":"2026-08-05 02:41:22","updated_at":"2026-08-05 02:41:22"},"facts":{"id":"rd-sudo-daemon-01","name":"Radagast Sudo Daemon","machine_name":"","owner":"agt_029","function":"Long-running privileged daemon that executes Radagast's allowlisted admin actions as the dedicated radagast OS user; caroladmin droids enqueue verified requests and never run sudo directly.","process_type":"ongoing","schedule":"continuous (systemd)","process_name":"carol-radagast-sudo.service","avatar_color":"#94a3b8","created_for":"CAROL-INI-1848","purpose":"Be the single OS-enforced executor of privileged admin actions on the VM.","duties":"Poll the admin-request queue; re-verify each request (authentic+active+reviewed); enforce the allowlist; execute via the radagast user's scoped sudo grant; write the admin-log.","constraints":"Only the allowlisted carol-* + nginx ops; no NOPASSWD:ALL; nothing outside the carol-* namespace; refuses unverified or unreviewed requests.","status":"running","gender":"","archetype":"executor","building_block":"support","service_override":null,"enabled":1,"task_key":"initiatives.blanket_planner","model_free":0},"page":{"type":"droid","page_class":"main","class_label":"Main page","kind_label":"Droid","kind_gloss":"","listed":true}}