Connect your own server or VM
You can give an agent your own Linux server or VM as its endue Computer. You run one install command on the machine, and the agent’s files and programs live there from then on.
When to use it
Section titled “When to use it”Use your own server when the work needs something only that machine has: access to your internal network, tools and data already installed, more CPU or disk than the default, or a machine in a region you chose. Any Linux machine you control works, such as a VPS at Vultr, an EC2 instance on AWS, or a server on premises.
If none of that applies, you do not need this page. An agent gets an endue Computer on endue cloud automatically the first time it needs one. See Devices.
What you need
Section titled “What you need”- Linux on x86_64 or aarch64. The program is a single static binary, so the distribution does not matter.
- systemd.
- Root access through
sudo. - Outbound internet access. endue Computer connects out to endue over a secure WebSocket, so you do not open any inbound port.
Install
Section titled “Install”-
Open Resources › Devices from the left sidebar and select Install on my device or server in the endue Computer group.
From one agent’s page in Agent Builder, Resources › Devices › Connect my server does the same for that agent.
-
Pick the agent and, optionally, a device name for the list (for example
build-server-01). Select Create install command.If the agent already has an endue Computer on endue cloud, you are asked whether to delete it and its files first. Cancel and nothing changes. See Replacing an agent’s endue cloud Computer.
-
Copy the command and run it on your server. It looks like this:
Terminal window curl -fsSL https://download.endue.ai/computer/install.sh | sudo sh -s -- \--endpoint <endpoint> --token <token> --instance <agent-id>The command contains a connection token for this agent. It is shown once. If you close the window before copying it, create a new command.
-
Wait for Connected. The dialog and the device list change to Connected a few seconds after the command finishes.
What the installer does
Section titled “What the installer does”-
Detects the architecture, downloads endue Computer, and checks its SHA-256 checksum. If the checksum does not match, it installs nothing.
-
Checks which profile your kernel supports.
-
Creates a system user named
enduethat cannot log in. -
For the agent, creates:
Path Owner and mode Holds /etc/endue-computer/<agent-id>.envroot, 0600The connection address, the token, and the settings you chose /var/lib/endue-computer/<agent-id>/workspaceendueThe agent’s workspace: the folder it works in /var/lib/endue-computer/<agent-id>/stateendueCheckpoints and saved files, outside the workspace -
Enables and starts a systemd service for the agent,
endue-computer@<agent-id>, and reports whether it connected.
Choosing what the agent can do
Section titled “Choosing what the agent can do”Add options to the end of the install command:
curl -fsSL https://download.endue.ai/computer/install.sh | sudo sh -s -- \ --endpoint <endpoint> --token <token> --instance <agent-id> \ --allow-exec git,python3 --no-network| Option | Default | Effect |
|---|---|---|
--allow-exec <list> | git,node,npm,npx,python3,pip3,curl | The programs the agent may run, comma-separated, without paths. --allow-exec "" turns off running programs entirely. |
--no-network | Network allowed | Programs the agent runs cannot use the network. |
--no-delete | Deleting allowed | The agent cannot delete files in its workspace. Tools such as git and npm delete lock and temporary files, so with the sandboxed profile they fail. |
--profile auto|sandboxed|managed | auto | Which profile to use. |
A program on the list that is not installed on the server is reported at install time. The agent gets “not installed” if it tries to run it.
An allowed program is not a limit on what that program does. Allowing node or python3 lets the agent run any code those can run, inside the profile’s boundary.
Profiles
Section titled “Profiles”| Profile | Needs | What programs the agent runs cannot do |
|---|---|---|
sandboxed | Linux 6.12 or later (Landlock ABI 6) | Read or write files outside the workspace folder. Everything under managed also applies. |
managed | Any other kernel, such as Ubuntu 22.04 (5.15) or the Ubuntu 24.04 GA kernel (6.8) | Become root or gain privileges. systemd hides /home, /root, and other agents’ folders, and makes the rest of the system read-only. There is no filesystem sandbox: programs can read any file the endue user can read. |
auto picks sandboxed when the kernel supports it and falls back to managed with a notice. If you ask for sandboxed on a kernel that does not support it, the installer stops without installing. Use managed only on a server or VM dedicated to the agent.
Adding another agent to the same server
Section titled “Adding another agent to the same server”One server can serve several agents. In Resources › Devices, open the menu on the server’s row and select Add agent, pick the agent, and run the new command on the same server.
Each agent gets its own service, settings file, and folders. The program and the endue user are shared. With the managed profile, systemd is what keeps each agent out of the others’ folders.
Starting, stopping, and logs
Section titled “Starting, stopping, and logs”Replace <agent-id> with the value after --instance in your command.
sudo systemctl status endue-computer@<agent-id> # is it runningsudo systemctl start endue-computer@<agent-id> # start itsudo systemctl stop endue-computer@<agent-id> # stop itsudo journalctl -u endue-computer@<agent-id> -f # follow the logWhile the service is stopped, the device shows Off and the agent tells you to start it. endue does not create a cloud Computer in its place.
Reinstalling
Section titled “Reinstalling”Running an install command again with the same --instance replaces the settings, including the token, and restarts the service.
You cannot create a new command while the agent’s server is connected. Stop the service on the server first, then create the command again.
Uninstalling
Section titled “Uninstalling”curl -fsSL https://download.endue.ai/computer/install.sh | sudo sh -s -- \ --uninstall --instance <agent-id>This stops and disables the agent’s service and deletes its settings file. The workspace and state folders stay unless you add --purge. Without --instance, every agent on the server is removed. When no agent is left, the program and the service definition are removed too.
Uninstalling on the server does not remove the device from endue, and removing it in endue does not uninstall it from the server. Do both: here, and Remove on the agent in the device’s row menu. See Removing a device.
Limits
Section titled “Limits”- Linux only, on x86_64 or aarch64. macOS and Windows versions are not available yet.
- One endue Computer per agent. An agent on your server cannot also have one on endue cloud, and an agent already on another server has to be removed there first.
- endue cannot start your server or the service. If either is down, the agent works without it.
- The agent can use tools on the server only while the service is connected. Programs it started in the background stop when the service stops.
- Without systemd, for example in some containers, add
--no-systemd. The installer puts the files in place and prints the command to start endue Computer yourself. The systemd protections above do not apply then. - If the service fails to start with
status=226/NAMESPACE, the machine cannot create mount namespaces, which happens in some LXC and OpenVZ containers. Use a full VM, or--no-systemd.