The fleet

Several Codemanys on one network form a fleet. Every member shows All machines and can open every other member, from its dashboard, the Mac app or codemany machines.

Machines can go down at any time, so no member is special: there is no leader. Jobs are never coordinated between machines; GitHub hands each job to one free runner.

Add a machine

  1. On your Mac, open Machines. Codemanys on your network show under Nearby.

  2. Choose Add to the fleet…. Your Mac asks the other machine for a code.

  3. The other machine's dashboard shows "… wants to add this machine" with a one-time code. On a server without a screen, codemany pair prints the same code.

  4. Type the code on your Mac. Both now trust each other.

Not under Nearby? Choose Add a machine… and type its address (192.168.1.50:8825), or from a terminal:

codemany machines add 192.168.1.50:8825 CODE

A code has 8 characters, lasts 10 minutes and allows 5 tries. Only an admin of the machine sees it: a CI job on that machine can't read it and join. Pairing with any member brings a machine into the whole fleet, and pairing members of two fleets merges them.

Rename and remove

codemany machines list
codemany machines rename ID NAME
codemany machines remove ID

Removing a member is final until you pair it again: a member that was offline can't bring it back, nor can the removed machine itself. It leaves the fleet when it hears (at once if it is online), and its runners keep working on their own.

Offline members

Every 10 seconds each member shares its member list with the others; that round is the heartbeat. A member that doesn't answer shows Offline · last seen <time>, and calls to it fail at once with that message instead of waiting for a timeout.

Addresses and ports

The dashboard takes port 8825, or the next free port from 8826 to 8835 when another user's Codemany on the same host holds it. A member heard at a new address is believed only after it proves who it is, so a spoofed announcement can only make a machine show up under Nearby.

How members trust each other

  • Each machine has its own key pair. Any two members derive a shared key without a secret ever crossing the network.
  • Every request between members is signed, carries the time and a one-time nonce, and is refused if it is more than 5 minutes off or replayed.
  • No bearer token is sent to another machine. The admin token you type into a browser stays on that machine.

Limits

Pairing runs over plain HTTP on your network. The code proves both sides to each other, and a passive listener can't learn the keys, but someone who can both read and rewrite traffic during the 10 minutes a code is live could pair in the middle. Membership is trust: every member can open and control every other member.

Kinds of machines

Each machine that runs jobs takes one machine seat of the subscription that owns its repos: Licensing and seats.