{"repo":"oddlama/elewrap","free":true,"listed":false,"github":"https://github.com/oddlama/elewrap","clone":"git clone https://github.com/oddlama/elewrap.git","description":"🥙 Controlled static privilege escalation utility with baked-in authentication rules. The most restrictive and lightweight replacement for sudo, doas or please.","language":"Nix","stars":20,"topics":["authentication","doas","please","privilege-escalation","sudo"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Building \\ Installation and Usage \\ Module options 🥙 Elewrap This is a tiny setuid wrapper program allowing for controlled elevation of privileges, similar to sudo, doas or please but with significantly less complexity and no dynamic configuration. The authentication rules are kept simple and will be baked in at compile-time, cutting down any attack surface to the absolute bare minimum. - 🔐 All authentication rules will be baked in. - ❄️ Provides a NixOS module to easily declare wrappers using elewrap to get rid of sudo. - 🌱 Tiny and simple program that is easy to audit. See for yourself. Building You can build an elewrap wrapper simply by cloning this repository and running cargo build: To set the authentication rules and target command, you will have to export some environment variables before building. These variables are available: Variable Type Default Description --- --- --- --- ELEWRAP TARGET USER Required - The target user to change to before executing the command. ELEWRAP TARGET COMMAND Required - The command to execute after changing to the target user. The executable path be absolute. The given string will be split on configured delimiter to allow defining arguments. ELEWRAP TARGET COMMAND DELIMITER Optional \"\\t\" The delimiter on which to split the target command. ELEWRAP TARGET COMMAND SHA512 Optional Unset If set, authenticates the target binary based on its sha512 hash before executing it. ELEWRAP ALLOWED USERS Optional Unset (empty list) A comma separated li","default_branch":null,"files":null,"tree":[],"storefront":"/r/oddlama","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/oddlama/elewrap/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}