cd /news/ai-agents/show-hn-valet-self-hosted-cloud-agen… · home › topics › ai-agents › article
[ARTICLE · art-144577] src=github.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Show HN: Valet – Self-Hosted Cloud Agents with Computers

Dropalltables released Valet, an MIT-licensed self-hosted platform that runs cloud coding agents such as Cursor cloud agents and Amp Orbs on a user's own Linux server or Mac via Docker Engine 24+ and Compose v2. Valet requires a Claude or Codex subscription or an Anthropic/OpenAI API key, plus an optional GitHub token for private repositories and pull requests, and exposes a web UI on port 3000 where users add a Claude setup-token, Codex sign-in or API key, and GitHub token. The project warns that agents have sudo inside their containers, so sandboxes should be treated as untrusted beyond their repo, and recommends blocking the 169.254.169.254 metadata endpoint on cloud hosts with an iptables DOCKER-USER rule.

read1 min views1 publishedOct 3, 2026
Show HN: Valet – Self-Hosted Cloud Agents with Computers
Image: Michielbdejong (auto-discovered)

self-hosted cursor cloud agents / amp orbs / etc

  • linux server or mac with docker engine 24+ and compose v2
  • claude/codex sub or anthropic/openai api key
  • github token for private repositories and pull requests (optional)
git clone https://github.com/dropalltables/valet
cd valet
cp .env.example .env   # set POSTGRES_PASSWORD, VALET_SECRET_KEY (openssl rand -base64 32), VALET_PASSWORD
docker compose --profile sandbox build
docker compose up -d --build

open http://localhost:3000 and add accounts under settings: a claude setup-token, a codex sign-in or api key, a github token. every env var is documented in .env.example.

on a domain: reverse proxy port 3000 with websockets, set VALET_BASE_URL, and point *.valet.example.com at the box with a wildcard cert. services live on those subdomains.

  1. docker compose resource from this repo. leave the domain field empty
  2. env: VALET_BASE_URL ,VALET_SERVICE_DOMAIN ,VALET_PROXY_NETWORK (the app's uuid),VALET_CERT_RESOLVER (a dns-challenge resolver you add to the proxy config)
  3. turn off "escape special characters in labels"
  • .valet/setup : runs once after clone
  • .valet/resume : runs on every wake
  • .valet/services.yaml : processes to keep running
services:
  web:
    command: npm run dev -- --port $PORT
    browser: true     # shows in the services tab
    health: /
  api:
    command: uv run uvicorn app:app --port $PORT
    port: 8000        # default: assigned

inside the sandbox: valet service start|list|logs|restart|remove, valet url <port>.

bun install && docker compose up -d db
VALET_DOCKER_NETWORK=valet_valet VALET_REPOS_VOLUME=valet_repos bun run dev:core
bun run dev:web

core holds the docker socket; only web publishes a port. agents have sudo in their container, so treat a sandbox as untrusted beyond its repo. on cloud hosts block metadata: iptables -I DOCKER-USER -d 169.254.169.254/32 -j DROP.

mit. see LICENSE.

── more in #ai-agents 4 stories · sorted by recency
── more on @valet 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/show-hn-valet-self-h…] indexed:0 read:1min 2026-10-03 · —