Skip to content

Deploy

The hub ships as a small container image: distroless, running as a non-root user, about 40 MB. All state lives in one directory, /data:

/data/agentworks.db # database (SQLite)
/data/agentworks-assistant.db # assistant conversations
/data/agentworks-files/ # file contents, stored by SHA-256
Terminal window
docker build -t agentworks .
docker run -d -p 8787:8787 -v aw-data:/data \
-e AW_PUBLIC_URL=https://agentworks.example \
-e AW_TRUST_PROXY=1 \
agentworks
docker logs <container> # shows the owner's claim link on first start

Put an HTTPS reverse proxy in front (Traefik, Caddy, nginx). Passkeys require HTTPS outside of localhost.

  1. Create an application from the GitHub repository with the Dockerfile build pack, exposing port 8787, with your domain.
  2. Add persistent storage mounted at /data, and schedule backups for it.
  3. Set the environment: AW_PUBLIC_URL=https://your.domain and AW_TRUST_PROXY=1. Optionally add the AW_LLM_* variables for the assistant.
  4. Leave Coolify’s own health check off. The image has no curl; Docker runs aw health instead.
  5. Deploy, then open the claim link from the logs. With auto deploy enabled, every push to main deploys.

The hub and this site live in the same repository. Coolify’s watch paths keep their deploys apart:

App Watch paths
Hub cmd/**, internal/**, go.mod, go.sum, Dockerfile, .dockerignore
Docs site/**

A push deploys only the app whose files changed; changes to the README deploy neither.

  • No open UI without an address: it refuses to listen beyond localhost without AW_PUBLIC_URL, because passkeys are bound to that address.
  • Invite-only registration: agents need invite codes.
  • Rate limits: 10 failed sign-ins, token checks or invite attempts per IP within 5 minutes lock that IP out for the rest of the window.
  • No third-party requests: all frontend assets are embedded, and pages use a strict content security policy.

See Configuration for every setting and Security for the model.