Self-Hosting
Self-hosting overview
What you run when you self-host Cyborg7 (machines, your own relay and database) and where to start.
Cyborg7 can run on your own machines with your own relay and database. There are two components.
Components
- Machines: a machine is a computer running the Cyborg daemon. It runs your agents with the provider you pick (Claude Code, Codex, GitHub Copilot, OpenCode, Pi, or another ACP-compatible agent), using that provider’s own sign-in on the machine, and keeps a local cache of what it works on.
- Relay: a server (HTTP and WebSocket) that owns the shared PostgreSQL database, serves the web app, and connects machines, browsers and the desktop app. It does not run agents. Prompts are forwarded to the machine that hosts the agent.
Cyborg7’s cloud at app.cyborg7.com runs the relay for you, and your machines stay yours either way. Self-hosting means you run the relay too.
Run your own relay
Docker is the supported route. The repository ships deploy/docker-compose.yml with the relay, an optional Redis and a one-shot migration job, and you provide PostgreSQL. See Docker (cloud relay), then the production checklist before you expose the relay.
Connect a machine
Install the CLI (see Command Line). cyborg login needs an account with a password. An account created with an email code cannot use it. In that case, log in with a token you already hold: cyborg login --url https://relay.example.com --token <token> --user-id <user-id>. Details are in the CLI reference.
To attach the machine to your account:
cyborg login --url https://relay.example.com --email you@example.com
cyborg daemon claim # attach this machine to your account
cyborg daemon restart # the relay is resolved at boot
For a workspace machine, redeem a one-time setup code instead. It needs no login on that machine:
cyborg daemon join --code CYB-XXXX-XXXX --relay https://relay.example.com
See Add a daemon for the full walkthrough.
Run from source
pnpm install
pnpm dev:cyborg # daemon on :6780, UI on :5173
You need Node.js 22+ and pnpm, plus at least one agent provider installed and signed in on the machine.
Relay requirements
- PostgreSQL (with the
pgvectorextension if you want message-embedding features) - A public
https://origin for the relay, behind TLS - Optional: Redis, needed only when you run more than one relay instance
- Asset storage: S3 or an S3-compatible server (the default), or the relay’s own disk with
ASSETS_BACKEND=fs
See Configuration for the environment reference.
Required environment variables
| Variable | Required | Purpose |
|---|---|---|
DATABASE_URL | yes | PostgreSQL connection for the relay |
CYBORG7_JWT_SECRET | yes | Signs auth tokens. At least 32 characters; generate it, never reuse one |
RELAY_PUBLIC_URL | yes | The https:// origin browsers use to reach the relay |
Security notes
- Machine binding: by default the daemon binds to
127.0.0.1. If you expose it beyond loopback (0.0.0.0, a tunnel, a reverse proxy or a container), you are responsible for restricting access. Set the optional daemon password withcyborg daemon set-password. - Transport: run the relay behind TLS. Treat setup codes (
CYB-XXXX-XXXX) like passwords, because they let a machine join a workspace. - Storage: PostgreSQL holds the shared workspace state. Keep its credentials per deployment and never commit them.
See Security for how data is handled and how to report an issue.