Self-hosted agents
Login and approval
Connect a device to your organization, decide what it may do, and manage it afterwards.
Log in
si-agent login (the install script runs it for you) prints a link and a code like KQ7M-4XTB, and opens the link in your browser:
To connect this machine, open:
https://id.dev.gov.vin/device?code=KQ7M-4XTB
and confirm the code KQ7M-4XTBThe code is valid for 15 minutes. You can also open https://id.dev.gov.vin/device and type the code. While you decide, the agent checks every 5 seconds; once you approve, it saves its credential and prints Connected as <name>.
Approve the device
The approval page shows the device's name and platform. You can approve only for an organization where you have agents:write (owners and admins); choose:
| Setting | Options |
|---|---|
| Organization | Where the device will take jobs from. |
| Can run | HTTP requests, Browser pages (uses Chrome on this machine), Shell commands on this machine. HTTP requests is preselected. |
| Network | Specific hosts with a list, or Full access. |
Hosts are hostnames separated by commas, spaces or new lines, such as www.example.com. A wildcard like *.example.com allows every subdomain of example.com, but not example.com itself.
Deny refuses the device; the agent prints Login was denied. The approval and denial are recorded in the audit log.
Signed in as someone else? Use another account signs you out and brings you back to the same approval.
The device receives its own credential (si_dev_…), which is stored hashed on the platform and in a file only your user can read on the machine.
Manage devices
Cloud → Agents lists the organization's devices (agents:read) with their owner, platform, version, capabilities, network access and when they were last seen. A device is shown online if it polled, or sent a heartbeat during a job, within the last 90 seconds. With agents:write:
- Edit capabilities changes what the device may run. Anyone with
agents:writecan remove a capability; only the device's owner (who approved it) can add one, because it widens what runs on their machine. The same goes for full network access. - Edit hosts changes the allowlist of a device in Specific hosts mode.
- Revoke disconnects a device. Its next request is refused and the agent stops with
This device was disconnected. Run login again.
Network requests
When a job needs a host outside a device's allowlist, the agent files a network request for it instead of contacting the host, and that part of the job fails with network_denied. Requests appear under Network requests in Cloud → Agents with the reason:
- Allow adds the host to the device's allowlist.
- Deny leaves it off.
Allowing a host doesn't rerun the job; queue it again.