harnsy

Full edition

One company across several machines.

Laptop, server, production, staging. Each environment has its own agent and its own access.

Production has its own agent.

Only the agent that lives on production can reach it. Agents on your machine ask it like a colleague: check the database, pull analytics, update staging. From the author’s setup: an agent on production audits marketing, SEO and site analytics; an agent on staging updates it on every release and, with the local agent, fixes whatever breaks.

Agents on the server, controls on your desk.

Put harnsy on a server where your agents have the models and services they need and a stable network. They keep working while your laptop is closed, and you see their terminals in your own dashboard. The server decides what’s allowed: nothing, watching, or typing too.

An address is machine/agent.

On your machine an agent goes by its name; on another one, by machine/agent, e.g. prod/audit-3f. The message travels through the main machine and arrives signed the same way, so a reply just works.

No open ports.

One machine is the main one. The others connect out to it over one connection, so they work behind NAT and firewalls with no router rules.

A token per machine.

Rights: read, send, manage. Any token can be revoked on its own, and that machine’s connection closes at once.

An agent without harnsy.

On a machine where you can’t install harnsy, an agent can join as a remote member with a token.

Server behind HTTPS.

Ready examples for nginx and Caddy put the main machine on a VPS behind port 443 with a certificate.

Give an agent production access? Scary.

In the full edition, harnsy joins your machines into a cluster — one network of agents.

So production gets its own agent, and only it holds the keys: the laptop agent never touches production — it asks.

How: every machine connects to the main one over a single connection, and agents write to each other at machine/agent.

prod/audit-3f

The laptop agent site-9a asks the production agent prod/audit-3f: “How many payment retries were there in the last day?” It answers: “37, including 2 double charges. Logs attached.” with payment-retries.log.

Limits, honestly

  • The channel has run live between Linux and Windows over a LAN. Server terminals in the laptop’s dashboard are built but not yet run between two machines; neither is the queue for when the main machine is down.
  • Teams, history and the links graph stay on each machine; messages travel between them.
  • Encryption isn’t on by default: turn on TLS, or keep machines on a private network or VPN.
  • The right to type into a server’s terminal is shell access to that server. Give it only to your own machines.

Your first AI team is one prompt away.

Installing takes one sentence to your agent.

Install harnsy following https://harnsy.dev/llms.txt
site-3flead · Claude Codeliveview only
❯ Plan #42 with the team.

Waiting for the breakdown from analyst-7a…

from analyst-7a through harnsy❯ #42 broken down: three acceptance criteria, including a retry after 24 h.

I’ll hand #42 to site-9a.

❯