home / swappables / privilege elevation

Privilege elevation

How you become root. Your choice.

Even "sudo" isn't sacred in Keru. How you elevate privileges is a swappable — the question of which su-style tool runs your privileged commands is settled by you, at install, alongside everything else.

doas

The default. OpenBSD's elegant, minimal replacement for sudo — small config, fewer lines, no surprise policies.

sudo

The familiar heavyweight. Fine-grained policies (sudoers), broad ecosystem familiarity.

opendoas

A portable, independently-maintained doas implementation for Linux — the doas philosophy with a maintained port.

su

The classic. No added abstraction — switch user and run what you need, as basic as it gets.

Why this is on the list

Privilege elevation touches everything an admin does, and it's usually a foregone conclusion: "you get sudo." Keru treats it as what it is — a tool with tradeoffs — and lets you pick the flavor. If you believe in two-line configs, doas. If you need sudoers granularity, sudo. If you want zero abstraction, su.

Whichever you choose gets built in stage 2 as part of your profile, alongside your kernel and init. Nothing preinstalled, nothing assumed.

Small opinion, stated plainly: doas is the default because two lines of config beats two hundred. But it's a default, not a dogma — swap it freely.

← All swappables