oslo.rootwrap
Oslo Rootwrap
Decision gist · record as of 2026-08-14
Yes, if you are deploying or extending OpenStack services that require controlled root command execution. The permissive Apache 2.0 license, active maintenance, low install friction, and zero known vulnerabilities make it a safe choice. If you need root command filtering outside OpenStack, verify that its policy model aligns with your requirements first.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.11 or later.
- Designed for OpenStack deployments; standalone use outside that context requires understanding its command-filtering policy model.
- Active maintenance with a release 35 days ago.
License · maintenance · safety
Apache-2.0 (permissive) — Apache License 2.0 (permissive): you may use, modify, and distribute this package freely in commercial and private projects, provided you retain the license notice.
last release 2026-07-10 (35 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 140,932 downloads/mo, #11,258 on PyPI
Alternatives
Verify before relying
pip install oslo.rootwrap
from oslo_rootwrap import cmd
# Configure and invoke rootwrap filtering on shell commands- Specific API surface and filtering rule syntax are not detailed in the excerpt; consult documentation for integration patterns.
- Performance characteristics under high command volume are not documented in the fact sheet.
What it is and what it does
oslo.rootwrap is an OpenStack library that sits between application code and the shell to enforce fine-grained permission policies on commands that need to run as root. Rather than granting blanket sudo access, it validates each command against a set of rules before allowing execution, reducing the attack surface when OpenStack services need elevated privileges.
The package is part of the OpenStack oslo namespace and is maintained as an active project. It has minimal dependencies (only debtcollector and pbr) and installs as a pure Python wheel, making it lightweight to integrate into OpenStack deployments or other systems that need controlled root command execution.
Use it for
- Restrict which shell commands OpenStack services can execute as root, enforcing a whitelist-based policy.
- Audit and log elevated-privilege command invocations for compliance and security monitoring.
- Prevent privilege escalation attacks by validating command arguments before sudo execution.
- Integrate permission filtering into multi-tenant cloud environments where isolation is critical.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are deploying or extending OpenStack services that require controlled root command execution.
The permissive Apache 2.0 license, active maintenance, low install friction, and zero known vulnerabilities make it a safe choice. If you need root command filtering outside OpenStack, verify that its policy model aligns with your requirements first.
Install
oslo-rootwrap on PyPI
Before you install
Active maintenance with a release 35 days ago. Low install friction: pure Python wheel with only two lightweight runtime dependencies (debtcollector and pbr). Supports current Python versions (3.11–3.14).
Requires Python 3.11 or later. Designed for OpenStack deployments; standalone use outside that context requires understanding its command-filtering policy model.
License in practice
Apache License 2.0 (permissive): you may use, modify, and distribute this package freely in commercial and private projects, provided you retain the license notice.
Quickstart
pip install oslo.rootwrap
from oslo_rootwrap import cmd
# Configure and invoke rootwrap filtering on shell commands
Verify before relying
- Specific API surface and filtering rule syntax are not detailed in the excerpt; consult documentation for integration patterns.
- Performance characteristics under high command volume are not documented in the fact sheet.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.11 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesdebtcollectorpbr |
| Maintenance | Actively maintained 35 days since the last release |
| First released | |
| Downloads | 140,932 / month, #11,258 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: OpenStackIntended Audience :: DevelopersIntended Audience :: Information TechnologyOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonTyping :: Typed |
Evidence: oslo_rootwrap-7.10.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “root command filtering”
- oslo.rootwraposlo.rootwrap provides fine-grained filtering of shell commands to…
- zip-filesProvides command-line tools to create zip files with arbitrary root…
- hepconverthepconvert converts between columnar file formats—currently ROOT and…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also oslo.policy · oslo.privsep · elevate · oslo.vmware · oslo.config · oslo.log · oslo.middleware · oslo.utils · oslo.limit · oslo.versionedobjects