{"wiki":null,"facts":{"id":"rd-sudo-daemon-01","name":"Radagast Sudo Daemon","machine_name":"","owner":"agt_029","function":"Long-running privileged daemon that executes Radagast's allowlisted admin actions as the dedicated radagast OS user; caroladmin droids enqueue verified requests and never run sudo directly.","process_type":"ongoing","schedule":"continuous (systemd)","process_name":"carol-radagast-sudo.service","avatar_color":"#94a3b8","created_for":"CAROL-INI-1848","purpose":"Be the single OS-enforced executor of privileged admin actions on the VM.","duties":"Poll the admin-request queue; re-verify each request (authentic+active+reviewed); enforce the allowlist; execute via the radagast user's scoped sudo grant; write the admin-log.","constraints":"Only the allowlisted carol-* + nginx ops; no NOPASSWD:ALL; nothing outside the carol-* namespace; refuses unverified or unreviewed requests.","status":"running","gender":"","archetype":"executor","building_block":"support","service_override":null}}