Install and pair
Runners overview: what runs on your machine, and managed against self-hosted.
Install a runner: the one-line installer, step by step.
Pairing: the device-code approval, and why no token is pasted.
A runner is the process that actually executes agent work. These pages cover installing one, pairing it to your account, and living with it day to day.
Install and pair
Runners overview: what runs on your machine, and managed against self-hosted.
Install a runner: the one-line installer, step by step.
Pairing: the device-code approval, and why no token is pasted.
Containment
The security model: the sandbox, the synthetic home, and the environment allowlist.
Proving containment with doctor: run the check yourself and read the result.
What runs inside
Coding agents: the four adapters and how a run picks one.
Agent credentials: capture, list, revoke, and one-time release.
Workspaces and git: checkouts, task branches, and who pushes.
Knowledge in runs: what an agent can look up mid-run.
Day 2
Upgrades and uninstall: re-run to upgrade, check status, remove cleanly.
Troubleshooting: symptom-first fixes for the failures runners hit.