Guide
Run Aulay in Docker.
One command turns any Docker host into a fleet machine: a home server, a NAS, a VPS you already run containers on. Agents you start in Aulay run inside the container, which comes with git, Node.js, pnpm, Claude Code and a headless Chromium for browser previews. Outbound connections only.
Using an AI coding agent on that machine? Copy these steps into it: it checks the machine and runs the install, and hands you the one sign-in step it can't do itself.
What it says
Set up the Aulay runtime in Docker on this machine so it joins my Aulay fleet. Guide: https://aulay.io/guides/docker
1. Check Docker. Run `docker info --format '{{.ServerVersion}} {{.Architecture}}'`. Docker Engine 24+ or Docker Desktop is required, on x86_64 or arm64. If docker is missing or permission is denied, stop and tell me what to fix.
2. Download the installer and start it. It builds the image first, which takes a few minutes:
curl -fsSL https://market.aulay.io/docker.sh -o /tmp/aulay-docker.sh && sh /tmp/aulay-docker.sh
3. Sign-in needs me: the installer prints a link and waits for a one-time code to be pasted into a terminal. Your shell has no terminal, so when it stops at sign-in, don't work around it. Tell me to run this in a terminal on this machine (an SSH session is fine), then wait for me to say it's done. The image is already built, so it goes straight to sign-in:
sh /tmp/aulay-docker.sh
4. Verify with `sh /tmp/aulay-docker.sh status`. The aulay-runtime container should be Up and its log should show it connected. Tell me the computer's name as it will appear in Aulay.- 1. Check your Docker host
- 2. Run the installer
- 3. Pair it from any browser
- 4. Verify it joined your fleet
- · Or do it by hand: docker run or Compose
1Check your Docker host
Any machine with Docker Engine 24 or newer, or Docker Desktop. Agents are mostly CPU-and-RAM bound while they work, so give the host at least 2 CPUs and 4 GB of RAM. The image is about 1.5 GB, and the volume grows with the repositories your agents clone.
No firewall changes are needed. The runtime only dials out over HTTPS (port 443), so there are no ports to publish.
2Run the installer
From a terminal on the Docker host:
$ curl -fsSL https://market.aulay.io/docker.sh | sh
It does four things:
- Fetches the image recipe (a Dockerfile and its entrypoint) from
market.aulay.io. - Builds the image as
aulay/runtime:local. The first build takes a few minutes. - Pairs the container with your account (step 3).
- Starts the
aulay-runtimecontainer in the background. Docker restarts it after a crash or a reboot.
The computer is named <hostname>-docker in Aulay. To pick another name, run it as curl -fsSL https://market.aulay.io/docker.sh | AULAY_NAME="Home server" sh.
3Pair it from any browser
The first time, the installer prints a sign-in link. Open it in a browser on any device, sign in to your Aulay account, and the page shows a one-time code. Paste that code back into the terminal. The container keeps its credentials in the aulay-runtime volume, so you pair only once.
Run it from an interactive shell (an SSH session is fine), not a non-interactive script. The pairing prompt needs your terminal.
4Verify it joined your fleet
Open Aulay on any device. The new computer appears within a few seconds, ready for sessions. To watch it connect:
$ docker logs -f aulay-runtime
Claude Code is already installed. Sign in to it once and the sign-in persists in the volume:
$ docker exec -it aulay-runtime claude
Other agent CLIs (Codex, Cursor Agent, OpenCode) are offered for install the first time you start one on this machine.
Or do it by hand
The same steps as the installer, if you'd rather run each one yourself. First fetch the recipe and build the image:
$ mkdir aulay-docker && cd aulay-docker$ curl -fsSLO https://market.aulay.io/docker/Dockerfile$ curl -fsSLO https://market.aulay.io/docker/aulay-entrypoint.sh$ docker build -t aulay/runtime:local .
Pair it once:
$ docker run -it --rm \$ -v aulay-runtime:/home/aulay --hostname my-docker aulay/runtime:local login
Then run it in the background with the same volume:
$ docker run -d --name aulay-runtime --restart unless-stopped \$ -v aulay-runtime:/home/aulay --hostname my-docker aulay/runtime:local
--hostname is the computer's name in Aulay. Use the same value in both commands, or add -e AULAY_NAME="Home server" to both to pick a display name.
Docker Compose
Save this as compose.yaml next to the files you fetched:
services:
runtime:
build: . # the Dockerfile you fetched above
image: aulay/runtime:local
container_name: aulay-runtime
hostname: my-docker # the computer's name in Aulay
restart: unless-stopped
volumes:
- aulay-runtime:/home/aulay
volumes:
aulay-runtime:
name: aulay-runtime$ docker compose build$ docker compose run --rm -it runtime login # first time only$ docker compose up -d
Good to know
- Updates are automatic
- Every start brings the runtime up to the latest build, and a running container updates itself whenever it's idle. Now and then, rebuild the image to refresh the OS, Node and Claude Code:
curl -fsSL https://market.aulay.io/docker.sh | sh -s -- update. That keeps the volume, so the computer stays paired. Set-e AULAY_SELF_UPDATE=0on the container to keep the runtime version that's already in the volume. - Installer commands
- The installer takes a command after
-s --:updaterebuilds the image and recreates the container,statusshows the container and its recent logs, andremoveunpairs the computer and removes the container, keeping the volume. For example,curl -fsSL https://market.aulay.io/docker.sh | sh -s -- status. - The volume is the computer
/home/aulayholds the pairing, the runtime, cloned repositories, agent worktrees and~/.claude. Keep the volume and you keep the same computer across rebuilds anddocker rm. Delete it (docker volume rm aulay-runtime) and you pair again as a new one.- Network footprint
- Outbound HTTPS/WSS to
*.aulay.io(and the release CDN for downloads). Nothing inbound, no published ports, no VPN. - Browser previews
- Chromium is included for the Browser Preview agent. It runs without its own sandbox, because Docker's default seccomp profile blocks it and the container already isolates it.
- Prefer a plain server install?
- On a VPS you control, the VPS guide installs the runtime as a system service with one command, no Docker needed.
That's a fleet machine.
Start an agent on it from your desktop, close the laptop, and check on it from your phone. The session lives in the container now.
Aulay AI