systemd-sentry · v0.1.0

Autonomous, zero-trust supervisor for systemd.

systemd-sentry (sentry) brings deterministic root-cause triage, sliding-window circuit-breaking, and guarded self-healing to systemd Linux environments. Built in 100% pure Rust with direct kernel syscalls, zero C dynamic library dependencies, zero open network listeners, and a strict <15MB RSS memory budget.

100% Pure Rust Zero Dynamic C Libs Zero TCP Listeners systemd Native Model Context Protocol Apache-2.0 / MIT

01Why 100% Pure Rust & Zero C Dependencies?

Traditional system daemons link against libsystemd.so, libdbus-1.so, and OpenSSL (libssl.so / libcrypto.so). This creates brittle ABI bindings, supply-chain CVE exposure, and dynamic linking failures during system recovery. systemd-sentry takes a zero-compromise approach:

02Zero-Trust Safety Engine & Circuit Breaker

AI inference is powerful for diagnosis, but handing autonomous shell execution to an LLM on production Linux servers is an operational disaster. systemd-sentry enforces strict separation of mechanism and policy:

03Local IPC & Zero Network Listeners

Security starts with zero exposure. systemd-sentry opens zero TCP ports. All communication occurs through authenticated local host channels:

04Engineering & Testing Metrics

200 / 200
Unit QA Tests Passed
87 / 87
4-Tier E2E Tests Passed
4
cargo-fuzz Targets
0
Dynamic C Libraries
≤ 256
Physical LOC / File
< 15 MB
Target Memory RSS

Every commit is verified against hard structural and security invariants: scripts/check_deps.sh enforces zero dynamic C linkage; scripts/check_loc.sh enforces single-function isolation and ≤256 LOC per file; and the entire test suite runs with zero panics in daemon paths.

05Quick Start & CLI Surface

Build from source with standard Rust toolchain:

git clone https://github.com/syntropd/sentry.git
cd sentry
cargo build --release

Interactive setup wizard (detects local routerd / llama.cpp / OpenAI endpoints):

systemd-sentry --setup

Validate configuration and policy drop-in syntax (pre-flight check, exits 0 or 78):

systemd-sentry check

Inspect system health and active circuit breaker states:

systemd-sentry status --json

On-demand root cause triage for any unit without waiting for failure:

systemd-sentry triage nginx.service

Live streaming event monitor (crashes, circuit breaker trips, remediations):

systemd-sentry monitor

Run the Model Context Protocol (MCP) server for external AI tools over stdio:

systemd-sentry mcp

06License

Licensed under either of Apache License, Version 2.0 or MIT license at your option. See LICENSE for details.