Guide

Run Aulay in Docker.

One command turns any Docker host into a fleet machine: a home server, a NAS, a VPS you already run containers on. Agents you start in Aulay run inside the container, which comes with git, Node.js, pnpm, Claude Code and a headless Chromium for browser previews. Outbound connections only.

Using an AI coding agent on that machine? Copy these steps into it: it checks the machine and runs the install, and hands you the one sign-in step it can't do itself.

What it says
Set up the Aulay runtime in Docker on this machine so it joins my Aulay fleet. Guide: https://aulay.io/guides/docker

1. Check Docker. Run `docker info --format '{{.ServerVersion}} {{.Architecture}}'`. Docker Engine 24+ or Docker Desktop is required, on x86_64 or arm64. If docker is missing or permission is denied, stop and tell me what to fix.
2. Download the installer and start it. It builds the image first, which takes a few minutes:
   curl -fsSL https://market.aulay.io/docker.sh -o /tmp/aulay-docker.sh && sh /tmp/aulay-docker.sh
3. Sign-in needs me: the installer prints a link and waits for a one-time code to be pasted into a terminal. Your shell has no terminal, so when it stops at sign-in, don't work around it. Tell me to run this in a terminal on this machine (an SSH session is fine), then wait for me to say it's done. The image is already built, so it goes straight to sign-in:
   sh /tmp/aulay-docker.sh
4. Verify with `sh /tmp/aulay-docker.sh status`. The aulay-runtime container should be Up and its log should show it connected. Tell me the computer's name as it will appear in Aulay.
  1. 1. Check your Docker host
  2. 2. Run the installer
  3. 3. Pair it from any browser
  4. 4. Verify it joined your fleet
  5. · Or do it by hand: docker run or Compose

1Check your Docker host

Any machine with Docker Engine 24 or newer, or Docker Desktop. Agents are mostly CPU-and-RAM bound while they work, so give the host at least 2 CPUs and 4 GB of RAM. The image is about 1.5 GB, and the volume grows with the repositories your agents clone.

Runs natively on x86_64 and ARM64, including Apple Silicon, AWS Graviton and a 64-bit Raspberry Pi. The installer builds for your Docker engine's architecture. On a Mac you use day to day, the desktop app is still the simpler fit.

No firewall changes are needed. The runtime only dials out over HTTPS (port 443), so there are no ports to publish.

2Run the installer

From a terminal on the Docker host:

$ curl -fsSL https://market.aulay.io/docker.sh | sh

It does four things:

  • Fetches the image recipe (a Dockerfile and its entrypoint) from market.aulay.io.
  • Builds the image as aulay/runtime:local. The first build takes a few minutes.
  • Pairs the container with your account (step 3).
  • Starts the aulay-runtime container in the background. Docker restarts it after a crash or a reboot.

The computer is named <hostname>-docker in Aulay. To pick another name, run it as curl -fsSL https://market.aulay.io/docker.sh | AULAY_NAME="Home server" sh.

3Pair it from any browser

The first time, the installer prints a sign-in link. Open it in a browser on any device, sign in to your Aulay account, and the page shows a one-time code. Paste that code back into the terminal. The container keeps its credentials in the aulay-runtime volume, so you pair only once.

Run it from an interactive shell (an SSH session is fine), not a non-interactive script. The pairing prompt needs your terminal.

4Verify it joined your fleet

Open Aulay on any device. The new computer appears within a few seconds, ready for sessions. To watch it connect:

$ docker logs -f aulay-runtime

Claude Code is already installed. Sign in to it once and the sign-in persists in the volume:

$ docker exec -it aulay-runtime claude

Other agent CLIs (Codex, Cursor Agent, OpenCode) are offered for install the first time you start one on this machine.

Or do it by hand

The same steps as the installer, if you'd rather run each one yourself. First fetch the recipe and build the image:

$ mkdir aulay-docker && cd aulay-docker
$ curl -fsSLO https://market.aulay.io/docker/Dockerfile
$ curl -fsSLO https://market.aulay.io/docker/aulay-entrypoint.sh
$ docker build -t aulay/runtime:local .

Pair it once:

$ docker run -it --rm \
$ -v aulay-runtime:/home/aulay --hostname my-docker aulay/runtime:local login

Then run it in the background with the same volume:

$ docker run -d --name aulay-runtime --restart unless-stopped \
$ -v aulay-runtime:/home/aulay --hostname my-docker aulay/runtime:local

--hostname is the computer's name in Aulay. Use the same value in both commands, or add -e AULAY_NAME="Home server" to both to pick a display name.

Docker Compose

Save this as compose.yaml next to the files you fetched:

services:
  runtime:
    build: .                   # the Dockerfile you fetched above
    image: aulay/runtime:local
    container_name: aulay-runtime
    hostname: my-docker        # the computer's name in Aulay
    restart: unless-stopped
    volumes:
      - aulay-runtime:/home/aulay

volumes:
  aulay-runtime:
    name: aulay-runtime
$ docker compose build
$ docker compose run --rm -it runtime login # first time only
$ docker compose up -d

Good to know

Updates are automatic
Every start brings the runtime up to the latest build, and a running container updates itself whenever it's idle. Now and then, rebuild the image to refresh the OS, Node and Claude Code: curl -fsSL https://market.aulay.io/docker.sh | sh -s -- update. That keeps the volume, so the computer stays paired. Set -e AULAY_SELF_UPDATE=0 on the container to keep the runtime version that's already in the volume.
Installer commands
The installer takes a command after -s --: update rebuilds the image and recreates the container, status shows the container and its recent logs, and remove unpairs the computer and removes the container, keeping the volume. For example, curl -fsSL https://market.aulay.io/docker.sh | sh -s -- status.
The volume is the computer
/home/aulay holds the pairing, the runtime, cloned repositories, agent worktrees and ~/.claude. Keep the volume and you keep the same computer across rebuilds and docker rm. Delete it (docker volume rm aulay-runtime) and you pair again as a new one.
Network footprint
Outbound HTTPS/WSS to *.aulay.io (and the release CDN for downloads). Nothing inbound, no published ports, no VPN.
Browser previews
Chromium is included for the Browser Preview agent. It runs without its own sandbox, because Docker's default seccomp profile blocks it and the container already isolates it.
Prefer a plain server install?
On a VPS you control, the VPS guide installs the runtime as a system service with one command, no Docker needed.

That's a fleet machine.

Start an agent on it from your desktop, close the laptop, and check on it from your phone. The session lives in the container now.