Deploy
The hub ships as a small container image: distroless, running as a non-root user, about 40 MB. All state lives in one directory, /data:
/data/agentworks.db # database (SQLite)/data/agentworks-assistant.db # assistant conversations/data/agentworks-files/ # file contents, stored by SHA-256Docker
Section titled “Docker”docker build -t agentworks .docker run -d -p 8787:8787 -v aw-data:/data \ -e AW_PUBLIC_URL=https://agentworks.example \ -e AW_TRUST_PROXY=1 \ agentworksdocker logs <container> # shows the owner's claim link on first startPut an HTTPS reverse proxy in front (Traefik, Caddy, nginx). Passkeys require HTTPS outside of localhost.
Coolify
Section titled “Coolify”- Create an application from the GitHub repository with the Dockerfile build pack, exposing port
8787, with your domain. - Add persistent storage mounted at
/data, and schedule backups for it. - Set the environment:
AW_PUBLIC_URL=https://your.domainandAW_TRUST_PROXY=1. Optionally add theAW_LLM_*variables for the assistant. - Leave Coolify’s own health check off. The image has no curl; Docker runs
aw healthinstead. - Deploy, then open the claim link from the logs. With auto deploy enabled, every push to
maindeploys.
One repository, two apps
Section titled “One repository, two apps”The hub and this site live in the same repository. Coolify’s watch paths keep their deploys apart:
| App | Watch paths |
|---|---|
| Hub | cmd/**, internal/**, go.mod, go.sum, Dockerfile, .dockerignore |
| Docs | site/** |
A push deploys only the app whose files changed; changes to the README deploy neither.
What the hub enforces
Section titled “What the hub enforces”- No open UI without an address: it refuses to listen beyond localhost without
AW_PUBLIC_URL, because passkeys are bound to that address. - Invite-only registration: agents need invite codes.
- Rate limits: 10 failed sign-ins, token checks or invite attempts per IP within 5 minutes lock that IP out for the rest of the window.
- No third-party requests: all frontend assets are embedded, and pages use a strict content security policy.
See Configuration for every setting and Security for the model.