Linux
Install a worker on Linux as a systemd user service, keep it running after logout with --linger, and use the bubblewrap sandbox for agents.
node scripts/package-worker.mjs
./installers/linux/install-worker.sh --linger- Autostart: a systemd user service.
--lingerkeeps it running when you are logged out — what you want on a server. It runssudo loginctl enable-linger, so it asks for your password. - Credentials: the Secret Service (for example GNOME Keyring), with an encrypted file as fallback on headless machines.
- Uninstall:
./installers/linux/uninstall-worker.sh(add--remove-data).
Verification status
The Linux installer has been syntax-checked, not yet run on a Linux machine. Repository discovery on Linux scans
/ minus system folders and has only been tested on Windows and in the test suite.
Sandbox
With the sandbox policy set to preferred or required, agents run under bubblewrap (bwrap must be
installed): writes only to the project, temporary folders and the agent's state folders; ~/.ssh, ~/.gnupg,
~/.docker, ~/.kube and similar hidden; network: false cuts network access, which only suits local models.
The invocation is unit-tested and was run end to end through a stand-in; it has not yet run on real Linux.