straza exec
Run a command through Straza policy, for an agent that has no hooks
On this page
Synopsis
The execution shim for agents that have no hook surface: the command is decided as a canonical shell.exec event against the local signed snapshot (same engine, spool, and fail-closed semantics as the harness hooks), then run with inherited stdio and exit-code passthrough. Denials print the rule reason and exit 2. Advisory on an open machine; boundary-grade inside a sandbox profile where this shim is the only exec surface.
straza exec -- <command> [args...] [flags]
See also
- straza: Straza client: enroll this machine, wire the hooks and decide each tool call