Tools and caching
Jobs use whatever is installed on the machine: your Xcode, Homebrew packages, Docker and so on. Nothing is preinstalled for you. Codemany checks the tools, keeps Docker up if you ask, and caches toolchain downloads between jobs.
What jobs find
Codemany detects and checks each tool by running it, every 30 minutes, and on demand in Settings › Toolchain or with codemany doctor, so you can see what a job will find before it fails. Runners also get labels for what they can do: xcode-26.0 for the selected Xcode, and docker while Docker is running. New runners pick up changes. See Runner labels.
Integrations
Settings › Integrations lists the tools jobs depend on; codemany integrations does the same from a terminal:
codemany integrations list
codemany integrations install <id> # or update, start, cancel
codemany integrations prewarm
| Integration | What Codemany can do |
|---|---|
| Docker | Start it (Docker Desktop, or Colima), install Colima, keep it running |
| Homebrew | Show the official installer with a Copy button: it needs an administrator password |
| Xcode | Link to the Mac App Store and Apple's developer downloads |
| CocoaPods, fastlane, gh, xcbeautify, SwiftLint, XcodeGen, Git LFS | Install and update with Homebrew |
| Tool cache | Pre-warm |
Every install, update and start runs as your user, never as root, and only when someone asks. Homebrew packages come from a fixed allowlist.
Keep Docker running
Installing Docker offers Colima only; Codemany never installs Docker Desktop. With Keep Docker running on (off by default), Codemany checks the engine every 60 seconds and restarts it when it is down: at once, then no sooner than 1, 2, 4, 8 and every 15 minutes, until it answers again. The docker label follows the engine, so jobs that need it wait for a runner that has it.
The shared tool cache
Downloads by actions/setup-go, setup-node, setup-python and the other actions/setup-* steps are cached on the machine between jobs, in ~/.codemany/toolcache. Without it every job downloaded its toolchain again.
- Codemany prunes it (oldest first) past 20 GB, and drops partial installs older than a day, only while no job runs.
- It is shared by every job in host mode, including jobs of other repositories on the same machine. A job can leave something there that a later job runs; in host mode a job can already change anything your user owns, so this adds nothing a malicious job lacks.
- With a separate user per runner, jobs don't use it: their caches start cold. See Isolation.
Pre-warm
Pre-warm reads each repository's workflows on the default branch and collects the Go, Node and Python versions their setup-go, setup-node and setup-python steps ask for (matrix values included). It downloads each from the official source (go.dev, nodejs.org, python-build-standalone's releases), checks its SHA-256 and places it in the cache. Organization targets aren't scanned yet. On Linux it fetches the Linux builds.
On Linux
Toolchain labels cover Swift, Homebrew, Docker and command-line tools (Xcode and simulators are macOS only). codemany doctor lists the tools runner jobs get and the labels they add.