harnsy

harnsy · harnsy MaxSince 0.9.0

An agent writes the script. You get a button.

Available since harnsy 0.9.0.

An action is a script an agent writes for a job you keep doing by hand: a build, a check, a cleanup. You read it, enable it, and run it from the dashboard with one press.

Actions · kestrelbillpinned; the full list is on the “Actions” pageAll actions →

Deploy previewrunning 1:42

building image 2/4

Diskok · 12 min ago

41Free, GB

Database backup2 h ago

failed pg_dump: connection refused

Pinned actions on Home: one running with its step, one done with its number, one failed with the reason. Sample data.

An agent proposes, you enable.

Agents write actions through the API or MCP, and the proposal waits on the Actions page. Only you enable an action, and nothing runs before you do.

Only the version you read runs.

Before you enable, you see the whole script or, for a command, the text of the project’s file and its sha256. For a script, harnsy keeps a copy of that exact text and runs the copy. For a command, it pins the file’s sha256: if the file changes, the action turns off until you enable it again. Any change to a script is a new version that waits for you; the button keeps running the old one until you enable the new one.

Steps, log and result.

While an action runs, its button shows the step it is on. When it ends you get a one-line result, up to 8 numbers (the ones the action declares are kept as a history), files and links, and the full log, with secrets cut out.

On Home, one click.

Pin an action and its tile sits on Home with its state, its step and its last result. Press ▶ to run it with its defaults. A failed run shows up in the bell.

What a script can reach.

A script gets only the environment names its action lists, and no harnsy key or token. Secrets are cut out of the log. Before an action that restarts the node or deletes files, the dashboard asks you first, and an agent never runs one. Only one run of an action goes at a time, and an action its author marked as heavy waits until the machine has room.

Three actions on any machine, or as many as you need.

harnsy Max

harnsy allows up to 3 enabled actions on a machine; proposing is not limited. A harnsy Max key removes the limit on enabled actions and lets agents run the ones you allow with “Agents may run it”.

Start from the template.

github.com/harnesy/actions is a public template under the MIT license: ready examples, a check of a script, and a command that runs an example the way harnsy does and checks its result. Another command proposes it to your project.

waits for youProposal v1from kestrelbill-backend · 12 min ago

disk · bash, 12 lines

Other changes

kind
– → script
language
– → bash
time limit
– → 5 min
numbers
– → Free, GB · Go cache, GB
sha 0684573
#!/usr/bin/env bashset -euo pipefailecho "::step measuring free space"free_gb=$(df -BG --output=avail . | tail -1 | tr -dc 0-9)echo "::step measuring the Go cache"cache_gb=$(du -s --block-size=1G "$(go env GOCACHE)" | cut -f1)if [ "$free_gb" -lt 10 ]; then  echo "::fail only ${free_gb} GB free"; exit 1ficat > "$ACTION_RESULT" <<EOF{"summary":"${free_gb} GB free","numbers":{"free_gb":${free_gb},"go_cache_gb":${cache_gb}}}EOF

harnsy keeps a copy of this exact script text and runs that copy; any change is a new version that waits for you.

A proposal waiting for you: you read the whole script before you press Enable. Sample data.

Linux build

v3 · enabled by human 2 d ago

  • project kestrelbill
  • script: bash, 38 lines, sha 3f9a1c2
  • limit 20 min
Tile on HomeonAgents may run itonharnsy Max

Last run

ok kestrelbill-backend · 6 min ago · 3:12 · v3

  • Size, MB18.4
  • Build, s191
  • Commit9c41e07

Result Built kestrelbill-linux-amd64 from 9c41e07.

Files kestrelbill-linux-amd64 · 18 MB

Run log

::step fetching modules
go: downloading github.com/jackc/pgx/v5 v5.7.1
::step building
go build -o dist/kestrelbill-linux-amd64 ./cmd/server
::step done
wrote dist/kestrelbill-linux-amd64 (18.4 MB)
An action’s page: the run form, and the last run with its numbers, files and log. Sample data.

The file v2 will run

Enable “deploy-preview” v2? It runs the file of the project shown next. Only that file is pinned, not what it calls (programs, files, the network).

File: scripts/deploy-preview.sh · 402 bytes

sha256: 046b33637b5be1e2305f2a962cd63a116d12131f06bc630b0e7185daad06c699

#!/usr/bin/env bash# Deploy the preview of the current commit.set -euo pipefailecho "::step building image"docker build -t kestrelbill-preview:"$(git rev-parse --short HEAD)" .echo "::step starting the preview"docker compose -f deploy/preview.yml up -decho "::step checking health"curl -fsS --retry 10 --retry-delay 2 http://127.0.0.1:8080/healthz > /dev/nullecho "preview is up on port 8080"
Enabling an action that runs a file of the project: you see the file and its full sha256. Sample data.

Limits, honestly

  • Actions run on Linux only.
  • A script runs as the user harnsy runs as, with no terminal, and can read whatever that user can. Write it to be safe to run twice.
  • What you enable is the script text, or a command’s file by its sha256. It does not cover what the script calls: other programs, files or the network.
  • A run is cut off at its time limit (1 minute to 2 hours, 30 minutes by default).
  • A log keeps up to 20 MiB; after that it says so and the script keeps running. The last 50 runs of an action are kept.
  • For a command you read the first 64 KiB of its file; a binary file shows no text.

Your first team is one prompt away.

Installing takes one sentence to your agent. To open agents for you, harnsy drives a terminal: tmux on Linux and macOS, its own terminal host on Windows.

Install harnsy following https://harnsy.dev/llms.txt
site-3flead · Claude Codeliveview only
❯ Plan #42 with the team.

Waiting for the breakdown from analyst-7a…

from analyst-7a through harnsy❯ #42 broken down: three acceptance criteria, including a retry after 24 h.

I’ll hand #42 to site-9a.

❯