Add cachy-auto-update: unattended background updates for CachyOS

A root systemd service applies pacman, AUR, Flatpak and AppImage updates on
its own, gated on battery state, gaming activity and whether anybody else is
using the package system. The CLI is deliberately two switches plus status.

No user password is stored anywhere: pacman runs as root directly, and the AUR
step - which makepkg forbids running as root - drops to a locked system account
that sudoers permits to call pacman without a password.
This commit is contained in:
Felitendo committed 2026-08-08 02:27:04 +02:00
1 parent 327da1dae3
commit ceb024d7be
28 files changed
+3856 -1

No files matched your search

+19
View File
@@ -0,0 +1,19 @@
# Privilege bridge for unattended AUR updates.
#
# makepkg, paru and yay refuse to run as root, so the update service runs them
# as the "cachy-auto-update" system account. That account then needs to be able
# to hand the finished packages to pacman without a human typing a password.
#
# The account is created by sysusers.d with no password and /usr/bin/nologin:
# it cannot be logged into, and only root can become it. Since the service that
# uses it already runs as root, this rule does not widen the trust boundary -
# it only lets an existing root process take the detour that makepkg demands.
#
# The rule is deliberately not restricted by arguments. paru and yay call
# pacman with argument lists that vary per transaction, so any pattern match
# would give the appearance of a restriction while breaking at random.
Defaults:cachy-auto-update !requiretty
Defaults:cachy-auto-update env_keep += "PACMAN"
cachy-auto-update ALL=(root) NOPASSWD: /usr/bin/pacman