Fleet Settings
Supervisors known to the manager. Metadata is durable: an offline supervisor keeps its alias and description and reappears fully named.
| Alias | |
| Description | |
| Daemon name | helena-cooper |
| First seen | … |
| Last seen | … |
To delete it and shut its daemon down, use the danger zone on its console.
| Alias | |
| Description | |
| Daemon name | lynn-walton |
| First seen | … |
| Last seen | … |
To delete it and shut its daemon down, use the danger zone on its console.
| Alias | |
| Description | |
| Daemon name | u-corp |
| First seen | … |
| Last seen | … |
To delete it and shut its daemon down, use the danger zone on its console.
| Alias | |
| Description | |
| Daemon name | christian-westmont |
| First seen | … |
| Last seen | … |
To delete it and shut its daemon down, use the danger zone on its console.
SSH keys
Public keys listed here can be installed on target machines. Private keys and passphrases are accepted only by POST and are never displayed.
No SSH keys are stored.
Add a supervisor over SSH
The manager connects to the target, installs the supervisor, and records a pending supervisor immediately. This console does not open the SSH connection.
Add a supervisor
The supervisor is probed over url:// before being admitted to the registry.
Launch your own supervisor daemon
A supervisor daemon runs on your own machine and serves AI-CLI sessions over url://. Started with
--register-with pointing at this console, it announces itself every ~60 seconds and appears in the list above automatically — no manual add needed. Requirements differ between the production and demo options below. Both use coursier and a JDK (17+); their runnable artifacts download from kotlin.directory.Real AI CLI sessions (recommended)
The supervisor is a privileged host daemon because it controls Docker. The launcher runs each AI CLI in a pinned, non-root guest container and drives it over an authenticated
url:// side channel. No AI CLI needs to be installed on the host PATH.- Docker: a reachable Docker daemon;
docker versionmust succeed. - Runtime: a JDK 17+ and coursier.
- On-demand guest image builds: a checkout of AiCliDockerGuestDaemonEmbedded containing
docker/build-images.sh. SetAICLI_GUEST_DEFINITIONS_DIRto that checkout; it defaults to./AiCliDockerGuestDaemonEmbedded. The checkout is unnecessary when all pinned guest image tags are already present.
coursier launch aicli.hostsupervisor:launcher-fatjar:0.1.9 \ -r https://kotlin.directory \ -- --register-with https://aiclisupervisor.wasmserver.com/
See the launcher README for the exact launch and guest-image configuration, including
AICLI_GUEST_IMAGES_JSON. As an optional advanced feature, the launcher can reuse host AI-CLI OAuth credentials by bind-mounting them into the guest and run the guest as the credentials' owner UID. Security: mounting live, writable OAuth credentials into a guest reachable from an unauthenticated surface is dangerous. A capability-scoped W3Wallet model is the planned follow-up.Fake/demo sessions (no AI CLI needed)
The fake-model service-server build serves an echoing fake model, so the whole console workflow can be exercised without any AI CLI installed. This is the service-server's fake PTY, not the Docker-guest launcher, and it does not require Docker or guest images.
coursier launch aicli.hostsupervisor:service-server-fakepty-fatjar:0.0.28 \ -r https://kotlin.directory \ -- --register-with https://aiclisupervisor.wasmserver.com/
Both announce over HTTPS (an HTTPS request can wake this lazily-started console, which relays the announcement to the durable manager). Daemons reachable over the P2P fabric can announce directly to the manager instead with
--register-with url://aiclisupervisormanager/. The daemon itself registers as url://vpn.<hostname>.aiclisupervisor/ on the fabric; that is the address this registry records and the one you would type into the add-by-URL form above.