Install the Hub
安裝主控端
Build the static Hub and architecture-specific Agent bundles, then bind the control plane to the tailnet.
建立靜態 Hub 與分架構 Agent bundle,並將控制平臺綁定在 tailnet。
AI-Intune tracks Linux, macOS, and Windows machines running AI agents and coding tools. Enroll a machine, assign an exact version, and inspect the evidence in one place.
AI-Intune 管理執行 AI agent 與 coding tools 的 Linux、macOS、Windows 機器。註冊端點、指派精確版號,再從同一處檢查證據。
A living process is not a healthy agent. A completed command is not a successful deployment. AI-Intune turns claims into inspectable evidence.
Process 還活著,不代表 agent 正常;指令執行完,不代表部署成功。AI-Intune 把每一個成功宣告都變成可檢查的證據。
The useful question is not “did the command run?” It is “what proves the machine reached the intended state?”
真正有用的問題不是「指令有沒有跑」,而是「什麼證明機器已經到達預期狀態?」
Install the Hub once. Enroll each endpoint with its platform bundle, then assign a profile that names exact supported packages.
主控端只需安裝一次。每台端點以對應平台的 bundle 註冊,再指派含精確版號且支援該平台的 profile。
Build the static Hub and architecture-specific Agent bundles, then bind the control plane to the tailnet.
建立靜態 Hub 與分架構 Agent bundle,並將控制平臺綁定在 tailnet。
A one-time token and the matching Agent bundle establish machine identity, check-ins, and a job channel.
一次性 token 與對應平台的 Agent bundle 建立機器身分、check-in 與工作通道。
Select pinned software for the target platform. The resolver checks dependencies, conflicts, and execution order.
選擇目標平台可用的釘版軟體。系統檢查依賴、衝突與執行順序。
The Agent verifies artifact bytes, exact versions, activation, and runtime health before the Hub marks the assignment complete.
Agent 會驗證 artifact bytes、精確版本、啟用狀態與 runtime 健康,Hub 才會將指派標記為完成。
The one-time token is never part of the install command.
一次性 token 不會寫在安裝指令裡。
Install Hub
The Hub's tailnet address is the only operator page.
Issue ticket
Paste the token when asked, or pass a token file whose mode is 0600.
Agent checks in
After the agent's first check-in, the machine page shows the time.
安裝 Hub
Hub 的 tailnet 位址,是唯一的管理頁。
發出票券
安裝程式問的時候再貼上,或改傳一個權限 0600 的 token 檔。
Agent 回報
Agent 第一次 check-in 以後,機器頁會出現時間。
Both OpenClaw and Hermes record the previous runtime before they try the new one.
OpenClaw 和 Hermes 都會先把舊的 runtime 記下來,再去試新的。
Snapshot previous
The snapshot has the config, the data, and which runtime was active.
Verify new
The new runtime has to pass its checks before this switch counts.
Restore previous
If those checks fail, the agent copies the snapshot back and checks health.
快照舊版
快照裡有設定、資料,和當時哪個 runtime 在跑。
驗證新版
新的 runtime 通過檢查,這次切換才算。
還原舊版
檢查沒過,Agent 就把快照抄回去,再看一次健康狀態。
Every visible state connects back to machine identity, immutable desired state, execution, verification, and audit evidence.
每一個畫面上的狀態,都能追溯到機器身分、不可變 desired state、執行結果、驗證與稽核證據。
A named machine roster, check-in ledger, health facts, credential state, change reports, and evidence drill-downs.
具名機器清單、check-in ledger、健康資訊、憑證狀態、變更報告與逐層證據檢視。
Artifacts are admitted by exact SHA-256 and size, then bound to immutable manifests and typed Agent adapters.
Artifact 以精確 SHA-256 與大小收錄,再綁定至不可變 manifest 與具型別的 Agent adapter。
Profiles select exact apps. The Hub resolves runtimes, platform support, conflicts, and a stable execution order.
Profile 選定精確 app;Hub 解析 runtime、平臺支援、衝突與穩定執行順序。
Leased jobs, prerequisite edges, time bounds, retries, deterministic failure propagation, and ordered revisions.
具 lease 的 job、前置依賴、時間界線、重試、確定性的失敗傳遞與 revision 順序。
Success means the expected files, exact version, activation target, and runtime checks all passed, not merely that a command exited.
成功代表預期檔案、精確版本、啟用目標與 runtime 檢查全部通過,而不只是指令離開。
Preview/apply digests, idempotency receipts, append-only assignment history, and recovery records make each change traceable.
Preview/apply digest、冪等收據、append-only 指派歷史與 recovery record,讓每次變更都可追溯。
If renewing the lease is refused, the adapter is cancelled.
續租失敗的話,Agent 會把轉接器停掉。
Take lease
The next job carries a lease token and the time it expires.
Run adapter
While that adapter runs, the agent renews the lease.
Post result
A 503 or 429 waits for Retry-After, and that wait is at most five minutes.
取得租約
下一張工作單帶著租約 token,還有它什麼時候到期。
執行轉接
轉接器還在跑的時候,Agent 會把租約續上。
送出結果
遇到 503 或 429 會等 Retry-After,最長五分鐘。
One Go Hub, one static Go Agent per endpoint, SQLite as the control ledger, and Tailscale as the private network and operator identity boundary.
一個 Go Hub、每端點一個靜態 Go Agent、SQLite 控制 ledger,以及作為私有網路與 operator 身分邊界的 Tailscale。
The Hub does not take the caller's word for who the admin is. It asks Tailscale about this connection.
管理者是誰,Hub 不聽呼叫端自己說,而是請 Tailscale 查這次連線。
Operator
WhoIs looks up the TCP source of this connection.
Hub
Forwarded and X-Forwarded-For are ignored. The caller wrote them.
Agent
It dials out, so this machine does not open an inbound control port.
管理者
WhoIs 拿這次連線的 TCP 來源去查。
Hub
Hub 不看 Forwarded,也不看 X-Forwarded-For,那是呼叫端自己寫的。
Agent
它主動連出,這台機器不用開連入的控制埠。
The Hub keeps its data in SQLite, which takes one write at a time.
Hub 的資料在 SQLite,一次只讓一個寫入。
Ask the Hub
A read uses the query-only pool, at most eight connections.
Data ledger
Writes line up for the one writer connection.
Busy is 503
After a 15 second wait, the Hub answers HUB_BUSY.
查詢 Hub
讀取走 query-only 那組,最多 8 條連線。
資料帳本
寫入要排隊等那唯一的一條連線。
忙碌即 503
排了 15 秒還輪不到,Hub 就回 HUB_BUSY。
Pin exact Node, Claude Code, Codex, Grok, and Antigravity versions for Linux, macOS, or Windows. On Linux, OpenClaw, Hermes, and BAT Server also have managed package paths. Each assignment keeps its artifact digest and verification evidence.
可為 Linux、macOS、Windows 釘選精確的 Node、Claude Code、Codex、Grok 與 Antigravity 版號。Linux 另有 OpenClaw、Hermes 與 BAT Server 的受管套件路徑。每次指派都保留 artifact digest 與驗證證據。
A profile holds at most one agent runtime. The plan then fills in what that runtime needs.
一份設定最多只放一個 agent runtime。計畫再補上那個 runtime 自己要的東西。
Choose profile
That profile is what you assign to the machine.
Resolve plan
primary-agent-runtime keeps OpenClaw or Hermes, and only one of them.
選擇設定
這份設定會指派到那台機器上。
解析計畫
primary-agent-runtime 只留 OpenClaw 或 Hermes,兩個不能一起。
The repository includes the Linux Hub installer, platform-specific Agent bundles, service definitions, and operator documentation. The steps shown here start with a Linux endpoint.
Repository 包含 Linux Hub 安裝器、分平台 Agent bundle、服務設定與 operator 文件。下列步驟以 Linux 端點為例。
make hub agent-bundles
./ops/install-hub.sh --listen 100.x.y.z:8787 …
/machines/enrollment · token + verified bundle
./install-agent.sh --hub http://100.x.y.z:8787