Skip to content

Connect your own server or VM

You can give an agent your own Linux server or VM as its endue Computer. You run one install command on the machine, and the agent’s files and programs live there from then on.

Use your own server when the work needs something only that machine has: access to your internal network, tools and data already installed, more CPU or disk than the default, or a machine in a region you chose. Any Linux machine you control works, such as a VPS at Vultr, an EC2 instance on AWS, or a server on premises.

If none of that applies, you do not need this page. An agent gets an endue Computer on endue cloud automatically the first time it needs one. See Devices.

  • Linux on x86_64 or aarch64. The program is a single static binary, so the distribution does not matter.
  • systemd.
  • Root access through sudo.
  • Outbound internet access. endue Computer connects out to endue over a secure WebSocket, so you do not open any inbound port.
  1. Open Resources › Devices from the left sidebar and select Install on my device or server in the endue Computer group.

    From one agent’s page in Agent Builder, Resources › Devices › Connect my server does the same for that agent.

  2. Pick the agent and, optionally, a device name for the list (for example build-server-01). Select Create install command.

    If the agent already has an endue Computer on endue cloud, you are asked whether to delete it and its files first. Cancel and nothing changes. See Replacing an agent’s endue cloud Computer.

  3. Copy the command and run it on your server. It looks like this:

    Terminal window
    curl -fsSL https://download.endue.ai/computer/install.sh | sudo sh -s -- \
    --endpoint <endpoint> --token <token> --instance <agent-id>

    The command contains a connection token for this agent. It is shown once. If you close the window before copying it, create a new command.

  4. Wait for Connected. The dialog and the device list change to Connected a few seconds after the command finishes.

  1. Detects the architecture, downloads endue Computer, and checks its SHA-256 checksum. If the checksum does not match, it installs nothing.

  2. Checks which profile your kernel supports.

  3. Creates a system user named endue that cannot log in.

  4. For the agent, creates:

    PathOwner and modeHolds
    /etc/endue-computer/<agent-id>.envroot, 0600The connection address, the token, and the settings you chose
    /var/lib/endue-computer/<agent-id>/workspaceendueThe agent’s workspace: the folder it works in
    /var/lib/endue-computer/<agent-id>/stateendueCheckpoints and saved files, outside the workspace
  5. Enables and starts a systemd service for the agent, endue-computer@<agent-id>, and reports whether it connected.

Add options to the end of the install command:

Terminal window
curl -fsSL https://download.endue.ai/computer/install.sh | sudo sh -s -- \
--endpoint <endpoint> --token <token> --instance <agent-id> \
--allow-exec git,python3 --no-network
OptionDefaultEffect
--allow-exec <list>git,node,npm,npx,python3,pip3,curlThe programs the agent may run, comma-separated, without paths. --allow-exec "" turns off running programs entirely.
--no-networkNetwork allowedPrograms the agent runs cannot use the network.
--no-deleteDeleting allowedThe agent cannot delete files in its workspace. Tools such as git and npm delete lock and temporary files, so with the sandboxed profile they fail.
--profile auto|sandboxed|managedautoWhich profile to use.

A program on the list that is not installed on the server is reported at install time. The agent gets “not installed” if it tries to run it.

An allowed program is not a limit on what that program does. Allowing node or python3 lets the agent run any code those can run, inside the profile’s boundary.

ProfileNeedsWhat programs the agent runs cannot do
sandboxedLinux 6.12 or later (Landlock ABI 6)Read or write files outside the workspace folder. Everything under managed also applies.
managedAny other kernel, such as Ubuntu 22.04 (5.15) or the Ubuntu 24.04 GA kernel (6.8)Become root or gain privileges. systemd hides /home, /root, and other agents’ folders, and makes the rest of the system read-only. There is no filesystem sandbox: programs can read any file the endue user can read.

auto picks sandboxed when the kernel supports it and falls back to managed with a notice. If you ask for sandboxed on a kernel that does not support it, the installer stops without installing. Use managed only on a server or VM dedicated to the agent.

One server can serve several agents. In Resources › Devices, open the menu on the server’s row and select Add agent, pick the agent, and run the new command on the same server.

Each agent gets its own service, settings file, and folders. The program and the endue user are shared. With the managed profile, systemd is what keeps each agent out of the others’ folders.

Replace <agent-id> with the value after --instance in your command.

Terminal window
sudo systemctl status endue-computer@<agent-id> # is it running
sudo systemctl start endue-computer@<agent-id> # start it
sudo systemctl stop endue-computer@<agent-id> # stop it
sudo journalctl -u endue-computer@<agent-id> -f # follow the log

While the service is stopped, the device shows Off and the agent tells you to start it. endue does not create a cloud Computer in its place.

Running an install command again with the same --instance replaces the settings, including the token, and restarts the service.

You cannot create a new command while the agent’s server is connected. Stop the service on the server first, then create the command again.

Terminal window
curl -fsSL https://download.endue.ai/computer/install.sh | sudo sh -s -- \
--uninstall --instance <agent-id>

This stops and disables the agent’s service and deletes its settings file. The workspace and state folders stay unless you add --purge. Without --instance, every agent on the server is removed. When no agent is left, the program and the service definition are removed too.

Uninstalling on the server does not remove the device from endue, and removing it in endue does not uninstall it from the server. Do both: here, and Remove on the agent in the device’s row menu. See Removing a device.

  • Linux only, on x86_64 or aarch64. macOS and Windows versions are not available yet.
  • One endue Computer per agent. An agent on your server cannot also have one on endue cloud, and an agent already on another server has to be removed there first.
  • endue cannot start your server or the service. If either is down, the agent works without it.
  • The agent can use tools on the server only while the service is connected. Programs it started in the background stop when the service stops.
  • Without systemd, for example in some containers, add --no-systemd. The installer puts the files in place and prints the command to start endue Computer yourself. The systemd protections above do not apply then.
  • If the service fails to start with status=226/NAMESPACE, the machine cannot create mount namespaces, which happens in some LXC and OpenVZ containers. Use a full VM, or --no-systemd.