Fleet Settings

Supervisors known to the manager. Metadata is durable: an offline supervisor keeps its alias and description and reappears fully named.
helena-cooperurl://vpn.helena-cooper.aiclisupervisor/daemon
Alias
Description
Daemon namehelena-cooper
First seen
…
Last seen
…
To delete it and shut its daemon down, use the danger zone on its console.
lynn-waltonurl://vpn.lynn-walton.aiclisupervisor/daemon
Alias
Description
Daemon namelynn-walton
First seen
…
Last seen
…
To delete it and shut its daemon down, use the danger zone on its console.
u-corpurl://vpn.u-corp.aiclisupervisor/daemon
Alias
Description
Daemon nameu-corp
First seen
…
Last seen
…
To delete it and shut its daemon down, use the danger zone on its console.
christian-westmonturl://vpn.christian-westmont.aiclisupervisor/daemon
Alias
Description
Daemon namechristian-westmont
First seen
…
Last seen
…
To delete it and shut its daemon down, use the danger zone on its console.

SSH keys

Public keys listed here can be installed on target machines. Private keys and passphrases are accepted only by POST and are never displayed.
No SSH keys are stored.

Generate a key

Upload a private key

Add a supervisor over SSH

The manager connects to the target, installs the supervisor, and records a pending supervisor immediately. This console does not open the SSH connection.
Authentication
Generate or upload a key above first.

Add a supervisor

The supervisor is probed over url:// before being admitted to the registry.

Launch your own supervisor daemon

A supervisor daemon runs on your own machine and serves AI-CLI sessions over url://. Started with --register-with pointing at this console, it announces itself every ~60 seconds and appears in the list above automatically — no manual add needed. Requirements differ between the production and demo options below. Both use coursier and a JDK (17+); their runnable artifacts download from kotlin.directory.

Real AI CLI sessions (recommended)

The supervisor is a privileged host daemon because it controls Docker. The launcher runs each AI CLI in a pinned, non-root guest container and drives it over an authenticated url:// side channel. No AI CLI needs to be installed on the host PATH.
  • Docker: a reachable Docker daemon; docker version must succeed.
  • Runtime: a JDK 17+ and coursier.
  • On-demand guest image builds: a checkout of AiCliDockerGuestDaemonEmbedded containing docker/build-images.sh. Set AICLI_GUEST_DEFINITIONS_DIR to that checkout; it defaults to ./AiCliDockerGuestDaemonEmbedded. The checkout is unnecessary when all pinned guest image tags are already present.
coursier launch aicli.hostsupervisor:launcher-fatjar:0.1.9 \
  -r https://kotlin.directory \
  -- --register-with https://aiclisupervisor.wasmserver.com/
See the launcher README for the exact launch and guest-image configuration, including AICLI_GUEST_IMAGES_JSON. As an optional advanced feature, the launcher can reuse host AI-CLI OAuth credentials by bind-mounting them into the guest and run the guest as the credentials' owner UID. Security: mounting live, writable OAuth credentials into a guest reachable from an unauthenticated surface is dangerous. A capability-scoped W3Wallet model is the planned follow-up.

Fake/demo sessions (no AI CLI needed)

The fake-model service-server build serves an echoing fake model, so the whole console workflow can be exercised without any AI CLI installed. This is the service-server's fake PTY, not the Docker-guest launcher, and it does not require Docker or guest images.
coursier launch aicli.hostsupervisor:service-server-fakepty-fatjar:0.0.28 \
  -r https://kotlin.directory \
  -- --register-with https://aiclisupervisor.wasmserver.com/
Both announce over HTTPS (an HTTPS request can wake this lazily-started console, which relays the announcement to the durable manager). Daemons reachable over the P2P fabric can announce directly to the manager instead with --register-with url://aiclisupervisormanager/. The daemon itself registers as url://vpn.<hostname>.aiclisupervisor/ on the fabric; that is the address this registry records and the one you would type into the add-by-URL form above.