Arbitrary shell (staging break-glass)
v0.2.2STAGING-ONLY BREAK-GLASS. Runs an arbitrary operator-supplied shell script on the runner host via `/bin/sh -c`. This is the one capability emisar is built to avoid: it bypasses the declared-action model entirely — whatever the script says, runs, as the runner's user. It exists so an agent can verify a fix interactively on a staging host before that fix is encoded as a proper declared action or runbook. DO NOT install this pack on production runners and DO NOT enable it in production. Its single action is critical-risk, so the default policy denies it until an operator deliberately opts in; every run is fully audited.
Install
emisar pack install
fetches this pack, re-validates it, and verifies its content hash against the
--hash
below before copying it into the runner's packs dir. That hash covers the exact bytes
this page was built from, so a tampered copy is rejected. The command reloads a
running daemon itself, so you don't need to restart it manually.
sudo emisar pack install shell --hash sha256:172c82284f5cb74f119e36bd4637524a7ae1fdf0dc96884ef4ec8af7c6d8dc4d
Setup
Operates on the local runner host via /bin/sh — no credentials needed. Intended ONLY for staging runners used to verify fixes before they are encoded as declared actions.
Notes
- STAGING ONLY. Do not install on production runners; do not enable in production.
- Runs as the runner's service user — keep that user least-privileged. The script can do anything that user can.
- The single action is critical-risk: the default cloud policy DENIES critical, so it cannot run until an operator adds a rule. Keep it at require_approval (e.g. a shell.run_script override) so every run is human-gated.
- Every invocation records the full script text in the local journal and the cloud audit log.
Install and configure a pack walks through the whole sequence on a host.
Actions 1 total
View on GitHub-
shell.run_script exec critical Critical: data loss or irreversible
Run a shell script (/bin/sh -c)
STAGING BREAK-GLASS — run an arbitrary shell script on the runner host via `/bin/sh -c`. Bypasses the declared-action model: whatever you pass runs verbatim, as the runner's user, with no per-argument schema and no allow/deny bounds beyond the timeout and output caps. Use this ONLY on a staging host to verify a fix before encoding it as a proper declared action or runbook — never as a substitute for one, and never in production. Keep scripts short and reviewable; the full text is recorded in the audit log.
View source on GitHub