Show HN: Valet – Self-Hosted Cloud Agents with Computers Dropalltables released Valet, an MIT-licensed self-hosted platform that runs cloud coding agents such as Cursor cloud agents and Amp Orbs on a user's own Linux server or Mac via Docker Engine 24+ and Compose v2. Valet requires a Claude or Codex subscription or an Anthropic/OpenAI API key, plus an optional GitHub token for private repositories and pull requests, and exposes a web UI on port 3000 where users add a Claude setup-token, Codex sign-in or API key, and GitHub token. The project warns that agents have sudo inside their containers, so sandboxes should be treated as untrusted beyond their repo, and recommends blocking the 169.254.169.254 metadata endpoint on cloud hosts with an iptables DOCKER-USER rule. self-hosted cursor cloud agents / amp orbs / etc - linux server or mac with docker engine 24+ and compose v2 - claude/codex sub or anthropic/openai api key - github token for private repositories and pull requests optional git clone https://github.com/dropalltables/valet cd valet cp .env.example .env set POSTGRES PASSWORD, VALET SECRET KEY openssl rand -base64 32 , VALET PASSWORD docker compose --profile sandbox build docker compose up -d --build open http://localhost:3000 http://localhost:3000 and add accounts under settings: a claude setup-token , a codex sign-in or api key, a github token. every env var is documented in .env.example . on a domain: reverse proxy port 3000 with websockets, set VALET BASE URL , and point .valet.example.com at the box with a wildcard cert. services live on those subdomains. 1. docker compose resource from this repo. leave the domain field empty 2. env: VALET BASE URL , VALET SERVICE DOMAIN , VALET PROXY NETWORK the app's uuid , VALET CERT RESOLVER a dns-challenge resolver you add to the proxy config 3. turn off "escape special characters in labels" - .valet/setup : runs once after clone - .valet/resume : runs on every wake - .valet/services.yaml : processes to keep running services: web: command: npm run dev -- --port $PORT browser: true shows in the services tab health: / api: command: uv run uvicorn app:app --port $PORT port: 8000 default: assigned inside the sandbox: valet service start|list|logs|restart|remove , valet url