Skip to main content

Arbitrary shell (staging break-glass)

v0.2.2

STAGING-ONLY BREAK-GLASS. Runs an arbitrary operator-supplied shell script on the runner host via `/bin/sh -c`. This is the one capability emisar is built to avoid: it bypasses the declared-action model entirely — whatever the script says, runs, as the runner's user. It exists so an agent can verify a fix interactively on a staging host before that fix is encoded as a proper declared action or runbook. DO NOT install this pack on production runners and DO NOT enable it in production. Its single action is critical-risk, so the default policy denies it until an operator deliberately opts in; every run is fully audited.

1 denied by default
Pack ID
shell
Vendor
emisar
OS
linux
Actions
1

Install

emisar pack install fetches this pack, re-validates it, and verifies its content hash against the --hash below before copying it into the runner's packs dir. That hash covers the exact bytes this page was built from, so a tampered copy is rejected. The command reloads a running daemon itself, so you don't need to restart it manually.

on the runner host
sudo emisar pack install shell --hash sha256:172c82284f5cb74f119e36bd4637524a7ae1fdf0dc96884ef4ec8af7c6d8dc4d

Setup

Operates on the local runner host via /bin/sh — no credentials needed. Intended ONLY for staging runners used to verify fixes before they are encoded as declared actions.

Notes

  • STAGING ONLY. Do not install on production runners; do not enable in production.
  • Runs as the runner's service user — keep that user least-privileged. The script can do anything that user can.
  • The single action is critical-risk: the default cloud policy DENIES critical, so it cannot run until an operator adds a rule. Keep it at require_approval (e.g. a shell.run_script override) so every run is human-gated.
  • Every invocation records the full script text in the local journal and the cloud audit log.

Install and configure a pack walks through the whole sequence on a host.

Actions 1 total

View on GitHub
  • shell.run_script exec critical Critical: data loss or irreversible

    Run a shell script (/bin/sh -c)

    STAGING BREAK-GLASS — run an arbitrary shell script on the runner host via `/bin/sh -c`. Bypasses the declared-action model: whatever you pass runs verbatim, as the runner's user, with no per-argument schema and no allow/deny bounds beyond the timeout and output caps. Use this ONLY on a staging host to verify a fix before encoding it as a proper declared action or runbook — never as a substitute for one, and never in production. Keep scripts short and reviewable; the full text is recorded in the audit log.

    View source on GitHub