Skip to content

Linux server

Rookery is designed to sit on a machine that stays on. This is the recommended installation, and the only platform with both filesystem confinement and a service that survives a reboot.

Terminal window
curl -fsSL https://rookery.cloud/install.sh | sh

The script installs a native binary. Prefer to inspect it first — it is short — or install from a package or archive instead: every release ships .deb and .rpm packages, plus archives with checksums and signatures. See Binary and packages.

Terminal window
rookery onboard

One interactive pass does the whole setup:

  • resolves the session key and the system key, and explains which one matters
  • creates the owner account — there is exactly one per installation
  • offers to install any missing host tools with your own package manager
  • offers the optional headless browser, if you do not already have it
  • reports the coder situation
  • installs and enables the systemd user service, with lingering turned on

Anything it skips is repeated in a closing Still to do list, so a partial setup never looks like a finished one.

Then open http://localhost:8080 and log in.

onboard sets this up for you. If you are doing it by hand, or installed from a .deb/.rpm and skipped onboarding, the packages ship a systemd user service. A user service runs as you, not as root, which is the right level of privilege for something that only ever touches its own data directory.

Terminal window
systemctl --user enable --now rookery
systemctl --user status rookery
journalctl --user -u rookery -n 50 --no-pager

One extra step matters on a server: a user service stops when you log out, unless lingering is enabled.

Terminal window
sudo loginctl enable-linger "$USER"

Without this, agents stop running the moment your SSH session ends — and the symptom is silence, not an error.

By default Rookery listens on all interfaces on port 8080.

VariableDefaultPurpose
ROOKERY_HOST0.0.0.0Bind address. Set 127.0.0.1 for loopback only.
ROOKERY_PORT8080Listen port.
ROOKERY_DATA_DIR~/.rookeryWhere everything is stored.

If you plan to connect services that use OAuth, you also need Rookery to know its own externally reachable address, because those providers redirect back to it after you approve access.

Terminal window
ROOKERY_PUBLIC_URL=https://rookery.example.com

On Linux, agent processes are confined at the filesystem level to their own workspace, so one workspace’s agents cannot read another’s. This uses a kernel feature that exists only on Linux — which is the main reason a Linux host is the recommended one.

You can confirm it is active:

Terminal window
rookery healthcheck

The response reports the protection status along with the version and which optional host tools are present.

Terminal window
rookery upgrade
rookery uninstall

upgrade fetches the latest release, verifies it against the release checksums, replaces the binary in place, and reports the version actually on disk afterwards. --version v0.1.4 moves to a named release instead.

uninstall removes the service and the binary, keeping your data unless you pass --purge.