systemd-sentry · v0.1.0
systemd-sentry (sentry) brings deterministic root-cause
triage, sliding-window circuit-breaking, and guarded self-healing to systemd
Linux environments. Built in 100% pure Rust with direct kernel syscalls,
zero C dynamic library dependencies, zero open network listeners, and a strict
<15MB RSS memory budget.
Traditional system daemons link against libsystemd.so, libdbus-1.so,
and OpenSSL (libssl.so / libcrypto.so). This creates brittle ABI bindings,
supply-chain CVE exposure, and dynamic linking failures during system recovery.
systemd-sentry takes a zero-compromise approach:
libsystemd, libdbus-1,
or OpenSSL. Uses pure Rust D-Bus (zbus) and pure Rust TLS
(rustls). Audited on every build by scripts/check_deps.sh.
rustix. Reads cgroups v2 resource accounting
(/sys/fs/cgroup/) and kernel Pressure Stall Information (/proc/pressure/)
using zero-allocation buffer pipelines.
$LISTEN_FDS (FDs 3..N), non-blocking
sd_notify ticker writing directly to $NOTIFY_SOCKET, and
first-class drop-in configuration support (/etc/systemd-sentry/policy.d/*.toml).
AI inference is powerful for diagnosis, but handing autonomous shell execution to an LLM
on production Linux servers is an operational disaster. systemd-sentry enforces
strict separation of mechanism and policy:
Open, and flapping units enter PermanentlyLocked,
preventing restart storm cascades.
PolicyGatekeeper, evaluating allowed actions against
/etc/systemd-sentry/policy.toml and policy.d/*.toml. Protected units
(systemd-journald, dbus, sshd, init.scope)
are completely untouchable.
Security starts with zero exposure. systemd-sentry opens zero TCP ports.
All communication occurs through authenticated local host channels:
SO_PEERCRED.
Local CLI queries communicate over /run/systemd-sentry/sentry.sock.
The kernel guarantees peer UID/GID credentials; mutating actions (e.g. reset)
require root authorization.
org.freedesktop.SystemdSentry on the system bus for standard
systemd and desktop integration.
stdio (systemd-sentry mcp) for direct,
secure integration with Claude Desktop, Cursor, and agentic workflows without network exposure.
Every commit is verified against hard structural and security invariants:
scripts/check_deps.sh enforces zero dynamic C linkage;
scripts/check_loc.sh enforces single-function isolation and ≤256 LOC per file;
and the entire test suite runs with zero panics in daemon paths.
Build from source with standard Rust toolchain:
git clone https://github.com/syntropd/sentry.git
cd sentry
cargo build --release
Interactive setup wizard (detects local routerd / llama.cpp / OpenAI endpoints):
systemd-sentry --setup
Validate configuration and policy drop-in syntax (pre-flight check, exits 0 or 78):
systemd-sentry check
Inspect system health and active circuit breaker states:
systemd-sentry status --json
On-demand root cause triage for any unit without waiting for failure:
systemd-sentry triage nginx.service
Live streaming event monitor (crashes, circuit breaker trips, remediations):
systemd-sentry monitor
Run the Model Context Protocol (MCP) server for external AI tools over stdio:
systemd-sentry mcp
Licensed under either of Apache License, Version 2.0 or
MIT license at your option. See LICENSE for details.