TIL ·
Give AI agents privileged access with pkexec
AI coding agents usually run unprivileged and stall when they need root — installing a package, writing under /etc, restarting a service. Instead of running the whole agent as root, tell it to escalate per command with pkexec:
When a command needs root, run it as `pkexec <command>` instead of failing or trying sudo.pkexec goes through Polkit, so each escalation gets its own auth prompt (desktop dialog or polkit agent), the environment is sanitized, and the action is logged. Example:
pkexec systemctl restart nginxCaveat: it needs a working polkit agent — on a headless SSH session with no agent it will fail, where sudo is still the right tool.