{"slug": "show-hn-valet-self-hosted-cloud-agents-with-computers", "title": "Show HN: Valet – Self-Hosted Cloud Agents with Computers", "summary": "Dropalltables released Valet, an MIT-licensed self-hosted platform that runs cloud coding agents such as Cursor cloud agents and Amp Orbs on a user's own Linux server or Mac via Docker Engine 24+ and Compose v2. Valet requires a Claude or Codex subscription or an Anthropic/OpenAI API key, plus an optional GitHub token for private repositories and pull requests, and exposes a web UI on port 3000 where users add a Claude setup-token, Codex sign-in or API key, and GitHub token. The project warns that agents have sudo inside their containers, so sandboxes should be treated as untrusted beyond their repo, and recommends blocking the 169.254.169.254 metadata endpoint on cloud hosts with an iptables DOCKER-USER rule.", "body_md": "self-hosted cursor cloud agents / amp orbs / etc\n\n- linux server or mac with docker engine 24+ and compose v2\n- claude/codex sub or anthropic/openai api key\n- github token for private repositories and pull requests (optional)\n\n```\ngit clone https://github.com/dropalltables/valet\ncd valet\ncp .env.example .env   # set POSTGRES_PASSWORD, VALET_SECRET_KEY (openssl rand -base64 32), VALET_PASSWORD\ndocker compose --profile sandbox build\ndocker compose up -d --build\n```\n\nopen [http://localhost:3000](http://localhost:3000) and add accounts under settings: a claude `setup-token`, a\ncodex sign-in or api key, a github token. every env var is documented in `.env.example`.\n\non a domain: reverse proxy port 3000 with websockets, set `VALET_BASE_URL`, and point\n`*.valet.example.com` at the box with a wildcard cert. services live on those subdomains.\n\n1. docker compose resource from this repo. leave the domain field empty\n2. env: `VALET_BASE_URL` ,`VALET_SERVICE_DOMAIN` ,`VALET_PROXY_NETWORK` (the app's uuid),`VALET_CERT_RESOLVER` (a dns-challenge resolver you add to the proxy config)\n3. turn off \"escape special characters in labels\"\n\n- `.valet/setup` : runs once after clone\n- `.valet/resume` : runs on every wake\n- `.valet/services.yaml` : processes to keep running\n\n```\nservices:\n  web:\n    command: npm run dev -- --port $PORT\n    browser: true     # shows in the services tab\n    health: /\n  api:\n    command: uv run uvicorn app:app --port $PORT\n    port: 8000        # default: assigned\n```\n\ninside the sandbox: `valet service start|list|logs|restart|remove`, `valet url <port>`.\n\n```\nbun install && docker compose up -d db\nVALET_DOCKER_NETWORK=valet_valet VALET_REPOS_VOLUME=valet_repos bun run dev:core\nbun run dev:web\n```\n\ncore holds the docker socket; only `web` publishes a port. agents have `sudo` in their\ncontainer, so treat a sandbox as untrusted beyond its repo. on cloud hosts block metadata:\n`iptables -I DOCKER-USER -d 169.254.169.254/32 -j DROP`.\n\nmit. see `LICENSE`.", "url": "https://wpnews.pro/news/show-hn-valet-self-hosted-cloud-agents-with-computers", "canonical_source": "https://github.com/dropalltables/valet", "published_at": "2026-10-03 19:01:43+00:00", "updated_at": "2026-10-03 19:36:13.466712+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "ai-infrastructure"], "entities": ["Valet", "Dropalltables", "Docker", "GitHub", "Anthropic", "OpenAI", "Claude", "Codex"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/show-hn-valet-self-hosted-cloud-agents-with-computers", "markdown": "https://wpnews.pro/news/show-hn-valet-self-hosted-cloud-agents-with-computers.md", "text": "https://wpnews.pro/news/show-hn-valet-self-hosted-cloud-agents-with-computers.txt", "jsonld": "https://wpnews.pro/news/show-hn-valet-self-hosted-cloud-agents-with-computers.jsonld"}}