Firetower

Add a machine

A worker is one binary on a machine you already have. Agents run on that machine, as the account you connect with, with its tools, its filesystem and its network. The machine is the unit of isolation: give a worker a VM of its own when that is what you want, and use the machine itself when that is the point — a Mac with Xcode on it, say.

Any machine will do. A VPS, a server in your office, a Mac mini under the desk, a spare laptop, a cloud VM — macOS or Linux, arm64 or x86_64. There are two requirements: an SSH account Firetower can reach, and git and tmux on the machine. Nothing else — not Node, not Docker.

A worker is optional, and a second one is the point: a new Firetower already runs sessions on itself. You add machines when you want agents running somewhere bigger, somewhere that stays awake, or somewhere with the tools a job needs.

#Give the machine Firetower's key

▶Run this onthe Firetower desktop client

Compute → Add a machine shows Firetower's public key. That is the one thing a machine can only get from a person, and it goes wherever that machine takes keys:

  • ~/.ssh/authorized_keys of the account agents should run as, on a machine you own — the dialog folds the exact lines under Adding it to authorized_keys by hand;
  • the provider's console, instance metadata or OS Login on Google Cloud;
  • the CA, where there is one.

It is public — safe to paste anywhere. Firetower makes its own SSH key; it never asks for yours. One pair for the whole installation, scoped to it: it opens nothing else you own, the private half never leaves the vault, and revoking it is deleting that one line, which cuts every machine at once.

#Add it

IP address or hostname

Where the machine is, from the Firetower. On a tailnet, its tailnet address. Add :2222 for a port that is not 22.

SSH account

The account to connect as. The worker and its agents run as this account, with its permissions.

Name

What you want to call it in the fleet.

Press Add it. Firetower connects and the panel says two things, told apart: whether SSH got in, and whether there is a worker.

#Install the worker

▶Run this onthe Firetower desktop client

A machine the key got into shows No worker — not Unreachable — with Install the worker beside it. Press it. Firetower runs its installer over the connection it just made: the worker built for that machine's shape lands in ~/.firetower/worker/bin. No sudo, nothing outside the account's home.

Then the worker measures the machine and the panel shows what is still missing, each with the command that installs it — brew install tmux on a Mac, sudo apt-get install -y tmux on Debian. Firetower never runs sudo on a machine; that is the one step it leaves to the person who has the password. Run it, press check again.

Agents are the last row. Press Install beside Claude Code or Codex and Firetower fetches the standalone binary the publisher ships onto the machine, under the worker's own directory. A claude already on the machine is used in preference.

Note

An SSH command gets a bare PATH — /usr/bin:/bin and little else — with nothing the account installed on it. The worker does not use that PATH: it asks the account's login shell for its own, adds the places package managers put tools, and runs every check and every agent with the result. A tool installed after the worker is found the next time it connects.

#By hand

▶Run this onthe machine that will run agents

The same installer, run from the machine — for whoever would rather watch it happen, and the one route that can answer a sudo prompt:

sh
curl -fsSL https://usefiretower.com/worker.sh | sh

As the account agents should run as. It works out what the machine is, prints the package manager's command for anything missing and asks before running it, downloads the release built for that shape, checks it against the release's SHA256SUMS, and ends with what firetower-worker doctor sees — the same checks Firetower runs over SSH. --authorize 'ssh-ed25519 …' adds the key in the same go; --agent claude-code fetches the agent; --skip-packages leaves the packages to you.

sh
~/.firetower/worker/bin/firetower-worker doctor --agent claude-code

shows the machine as Firetower sees it, whenever you want to check.

#Next

Update it when the Firetower moves on → Update.