For privilege separation reasons, probably makes sense to have this run as a subprocess like Nix does.