STRAZAdocs

straza exec

Run a command through Straza policy, for an agent that has no hooks

On this page

Synopsis

The execution shim for agents that have no hook surface: the command is decided as a canonical shell.exec event against the local signed snapshot (same engine, spool, and fail-closed semantics as the harness hooks), then run with inherited stdio and exit-code passthrough. Denials print the rule reason and exit 2. Advisory on an open machine; boundary-grade inside a sandbox profile where this shim is the only exec surface.

straza exec -- <command> [args...] [flags]

See also

  • straza: Straza client: enroll this machine, wire the hooks and decide each tool call

Search documentation

Search page titles, commands, and article text.

↑ ↓ Choose resultEnter OpenEsc Close