Problem / Motivation
There is no way to install failproofai on a machine where you can't sudo. I hit this running the Jev Buildathon setup inside a container: failproofai config wants to install the failproofaid systemd service, and without root it stops dead:
Installing failproofaid — needs sudo once.
Could not get root, so setup stopped before changing anything.
Re-run once you can use sudo: failproofai config
Check what it needs: systemctl status failproofaid@sandbox.service
Nothing was changed.
Containers, rootless CI, and locked-down dev boxes are exactly where agent CLIs get evaluated a lot of the time, and today those machines simply can't use the product: hooks are never wired, so nothing enforces or observes.
The catch is that the codebase already supports running daemonless - in-process evaluation is the Windows fallback, and configure-wizard.ts (the "back to in-process" path around line 1424) shows the mode working. Setup just never offers it: on a supported platform daemonWanted = daemonSupported && !daemonAlreadyRunning (line 875), with no opt-out.
Proposed Solution
A rootless path in failproofai config - e.g. --no-daemon (or --in-process) that wires the hooks and evaluates in-process, plus a line in the sudo-abort message naming the flag. The abort message is the moment every rootless user sees, so it should point at the way forward rather than only "re-run once you can use sudo".
Alternatives Considered
- Document a manual rootless setup (write the hook config by hand, skip the daemon). Works, but every container user rediscovers it.
- Detect the missing elevation and offer the in-process choice interactively, instead of a flag.
Happy to take a stab at the PR if you have a preference on the shape.
Additional Context
Version 1.0.8-beta.0, Node 22, Linux (container without sudo). Repro: any Docker container without sudo - npm i -g failproofai@beta && failproofai config. (The exit code is fine - the bin exits 1 on this abort; the dead end is the missing alternative, not the error handling.)
Problem / Motivation
There is no way to install failproofai on a machine where you can't sudo. I hit this running the Jev Buildathon setup inside a container:
failproofai configwants to install the failproofaid systemd service, and without root it stops dead:Containers, rootless CI, and locked-down dev boxes are exactly where agent CLIs get evaluated a lot of the time, and today those machines simply can't use the product: hooks are never wired, so nothing enforces or observes.
The catch is that the codebase already supports running daemonless - in-process evaluation is the Windows fallback, and
configure-wizard.ts(the "back to in-process" path around line 1424) shows the mode working. Setup just never offers it: on a supported platformdaemonWanted = daemonSupported && !daemonAlreadyRunning(line 875), with no opt-out.Proposed Solution
A rootless path in
failproofai config- e.g.--no-daemon(or--in-process) that wires the hooks and evaluates in-process, plus a line in the sudo-abort message naming the flag. The abort message is the moment every rootless user sees, so it should point at the way forward rather than only "re-run once you can use sudo".Alternatives Considered
Happy to take a stab at the PR if you have a preference on the shape.
Additional Context
Version 1.0.8-beta.0, Node 22, Linux (container without sudo). Repro: any Docker container without sudo -
npm i -g failproofai@beta && failproofai config. (The exit code is fine - the bin exits 1 on this abort; the dead end is the missing alternative, not the error handling.)