Add a machine
A worker is one binary on a machine you already have. Agents run on that machine, as the account you connect with, with its tools, its filesystem and its network. The machine is the unit of isolation: give a worker a VM of its own when that is what you want, and use the machine itself when that is the point — a Mac with Xcode on it, say.
Any machine will do. A VPS, a server in your office, a Mac mini under the
desk, a spare laptop, a cloud VM — macOS or Linux, arm64 or x86_64. There are
two requirements: an SSH account Firetower can reach, and git and tmux on
the machine. Nothing else — not Node, not Docker.
A worker is optional, and a second one is the point: a new Firetower already runs sessions on itself. You add machines when you want agents running somewhere bigger, somewhere that stays awake, or somewhere with the tools a job needs.
#Give the machine Firetower's key
▶Run this onthe Firetower desktop client
Compute → Add a machine shows Firetower's public key. That is the one thing a machine can only get from a person, and it goes wherever that machine takes keys:
~/.ssh/authorized_keysof the account agents should run as, on a machine you own — the dialog folds the exact lines under Adding it to authorized_keys by hand;- the provider's console, instance metadata or OS Login on Google Cloud;
- the CA, where there is one.
It is public — safe to paste anywhere. Firetower makes its own SSH key; it never asks for yours. One pair for the whole installation, scoped to it: it opens nothing else you own, the private half never leaves the vault, and revoking it is deleting that one line, which cuts every machine at once.
#Add it
- IP address or hostname
Where the machine is, from the Firetower. On a tailnet, its tailnet address. Add
:2222for a port that is not 22.- SSH account
The account to connect as. The worker and its agents run as this account, with its permissions.
- Name
What you want to call it in the fleet.
Press Add it. Firetower connects and the panel says two things, told apart: whether SSH got in, and whether there is a worker.
#Install the worker
▶Run this onthe Firetower desktop client
A machine the key got into shows No worker — not Unreachable — with
Install the worker beside it. Press it. Firetower runs its installer over
the connection it just made: the worker built for that machine's shape lands in
~/.firetower/worker/bin. No sudo, nothing outside the account's home.
Then the worker measures the machine and the panel shows what is still missing,
each with the command that installs it — brew install tmux on a Mac,
sudo apt-get install -y tmux on Debian. Firetower never runs sudo on a
machine; that is the one step it leaves to the person who has the password.
Run it, press check again.
Agents are the last row. Press Install beside Claude Code or Codex and
Firetower fetches the standalone binary the publisher ships onto the machine,
under the worker's own directory. A claude already on the machine is used in
preference.
Note
An SSH command gets a bare PATH — /usr/bin:/bin and little else — with
nothing the account installed on it. The worker does not use that PATH: it asks
the account's login shell for its own, adds the places package managers put
tools, and runs every check and every agent with the result. A tool installed
after the worker is found the next time it connects.
#By hand
▶Run this onthe machine that will run agents
The same installer, run from the machine — for whoever would rather watch it
happen, and the one route that can answer a sudo prompt:
curl -fsSL https://usefiretower.com/worker.sh | shAs the account agents should run as. It works out what the machine is, prints
the package manager's command for anything missing and asks before running it,
downloads the release built for that shape, checks it against the release's
SHA256SUMS, and ends with what firetower-worker doctor sees — the same
checks Firetower runs over SSH. --authorize 'ssh-ed25519 …' adds the key in
the same go; --agent claude-code fetches the agent; --skip-packages leaves
the packages to you.
~/.firetower/worker/bin/firetower-worker doctor --agent claude-codeshows the machine as Firetower sees it, whenever you want to check.
#Next
Update it when the Firetower moves on → Update.