Headless Mode
Run Autohand Code on DigitalOcean Droplets
Use a Droplet as a simple always-on Autohand Code runner with SSH access, snapshots, monitoring, and optional doctl automation.
Provider docs used
This tutorial follows provider documentation for current Droplet creation options and defaults. Keep this external guide open while you work.
Step 1: Create a Droplet
- Open the DigitalOcean Control Panel and choose Create, then Droplets.
- Select an Ubuntu LTS image.
- Select a region close to your Git host, artifact registry, or team.
- Choose a CPU and memory size large enough for your repository tests.
- Select SSH key authentication. Avoid password login for automation hosts.
- Enable monitoring, add tags such as
autohandandrunner, and assign the Droplet to the correct project. - Create the Droplet and wait for the public IP address.
Step 2: Connect and harden SSH
ssh root@203.0.113.10
adduser --disabled-password --gecos "" autohand
usermod -aG sudo autohand
rsync --archive --chown=autohand:autohand ~/.ssh /home/autohand
su - autohand
Use a DigitalOcean Cloud Firewall or host firewall to allow SSH only from your trusted IP ranges. Take a snapshot after the base runner setup is complete.
Step 3: Install Autohand Code
sudo apt-get update
sudo apt-get install -y ca-certificates curl git build-essential
node --version
npm --version
npm install -g autohand-cli
autohand --version
Step 4: Configure secrets and repository access
mkdir -p ~/.autohand ~/.ssh ~/work ~/logs
chmod 700 ~/.autohand ~/.ssh
cat > ~/.autohand/env <<'EOF'
# Variables your jobs need, such as a Git host token
export GH_TOKEN="your-git-host-token"
EOF
chmod 600 ~/.autohand/env
# Sign in once as the runner user. The command prints a URL and a
# one-time code that you can open on any device.
autohand login
ssh-keygen -t ed25519 -C "autohand-digitalocean-runner" -f ~/.ssh/github-autohand
Signing in connects the runner to your Autohand account and selects the Autohand provider with the Fantail model, a fast coding model that suits review and maintenance jobs. Add --model moa to jobs that need repository-wide reasoning, such as refactor plans. Moa is available on Pro plans and above. See Autohand models.
Add the public key to your Git host as a deploy key. Use read-only access for review jobs and write access only for jobs that push branches.
Step 5: Clone and run Autohand Code
source ~/.autohand/env
cd ~/work
GIT_SSH_COMMAND="ssh -i ~/.ssh/github-autohand" git clone git@github.com:your-org/your-repo.git
cd your-repo
autohand -p "Review this repository and write a short risk summary" \
--restricted \
--output-format stream-json | tee -a ~/logs/first-review.jsonl
Step 6: Automate with doctl or cron
DigitalOcean documents both Control Panel creation and automated Droplet creation with the official doctl CLI. Use doctl if you want disposable Autohand Code runners for specific jobs.
# Example shape; choose current region, size, image, and SSH key IDs from doctl list commands.
doctl compute droplet create autohand-runner \
--region nyc3 \
--size s-2vcpu-2gb \
--image ubuntu-24-04-x64 \
--ssh-keys YOUR_SSH_KEY_ID \
--tag-name autohand
For an always-on runner, schedule jobs directly on the Droplet.
0 8 * * 1-5 . $HOME/.autohand/env && cd $HOME/work/your-repo && git pull --ff-only && autohand -p "Review changes and summarize action items" --restricted --output-format stream-json >> $HOME/logs/daily-review.jsonl 2>&1
Operations checklist
- Use Cloud Firewalls for SSH access control.
- Snapshot the Droplet after installing Node.js, Git, Autohand Code, and base dependencies.
- Use tags so billing and inventory reports can identify Autohand Code runners.
- Destroy disposable runners after the job finishes.
- Keep model provider keys separate from the DigitalOcean API token used by
doctl.