Hybrid Execution
Vagaris runs work in two places and keeps one authority. The server owns every run, lease, approval and piece of evidence; a run may execute on the server or on an enrolled machine, and the governance is the same either way.
Server-hosted runs
The scheduler and vagaris heartbeat run invoke an agent on the server through its adapter. The server picks the runtime, applies the seat's policy and records the run. From the CLI you observe and control it:
vagaris heartbeat run --agent-id <agent-id> --source on_demand --trigger manual
vagaris runctl history --agent-id <agent-id>
vagaris runctl attach --run-id <run-id>
--source is one of timer, assignment, on_demand, automation; --trigger is manual, ping, callback or system.
CLI-hosted runs
vagaris dev claims a queued run and executes it on your machine under a verified lease (Developer Mode). The server still decides whether the claim is allowed, verifies the lease on every run, evaluates scope requests and privileged acts, and receives the evidence. What moves to your machine is the executor process and its worktree — not authority.
Use CLI hosting when the work needs your local repository state, tools or credentials that the server host does not have, or when you want to watch the agent in your own terminal.
Binding runs to a machine
Enrol the machine once (Node Enrolment), then present its id when claiming:
vagaris node status --json
vagaris dev --agent-id <agent-id> --run-id <run-id> --node-id <node-id>
A lease issued to that node is refused if another node presents it. vagaris node doctor proves the machine still holds its attestation key, and vagaris node revoke ends its ability to claim. Exit codes 8 (lease invalid) and 9 (node revoked) are the two refusals you will see from this path.
Several local instances
For development on Vagaris itself, the worktree commands create isolated instances per git worktree, each with its own config, ports and data:
vagaris worktree:make feature-x
vagaris worktree:list
vagaris worktree env
vagaris worktree:cleanup feature-x
worktree init, worktree reseed and worktree repair manage the repo-local instance in the current worktree; worktree:merge-history previews or imports issue and comment history from another worktree. These are distinct from the per-run worktrees dev creates.
Deterministic SSH fixtures for testing live under vagaris env-lab up|status|down|doctor.
Local instance to Vagaris Cloud
A local instance can push a company into a Vagaris Cloud stack:
vagaris cloud connect https://<cloud-stack-url>
vagaris cloud push --company <company-id> --dry-run
vagaris cloud push --company <company-id>
cloud connect authorises this instance against the remote (browser flow; --no-browser prints the URL instead). cloud push previews or applies the transfer; --max-entities-per-chunk bounds each chunk and --remote-url overrides the stored connection. A conflict exits 2 and a schema mismatch exits 3, so a script can tell "someone changed the remote" from "upgrade first".
Portable company packages
Moving a company between instances without the cloud goes through export and import:
vagaris company export <company-id> --out ./exports/acme --include company,agents,skills
vagaris company import ./exports/acme --target new --new-company-name "Acme" --dry-run