Install Jarvis

Choose how you run it. Local installs favour the terminal workspace. Server installs favour the browser. In every case: automation does the work; you set direction and watch outcomes.

Latest beta: v0.3.0-beta.87 · Release page →

Community · power users

Linux binary

Static SQLite, no Zig required. Current beta: v0.3.0-beta.87 (x86_64, glibc).

curl -fsSL -O https://git.sovereign-society.org/libertaria/Jarvis/releases/download/v0.3.0-beta.87/jarvis-0.3.0-beta.87-x86_64-linux.tar.gz
curl -fsSL -O https://git.sovereign-society.org/libertaria/Jarvis/releases/download/v0.3.0-beta.87/jarvis-0.3.0-beta.87-x86_64-linux.sha256
sha256sum -c jarvis-0.3.0-beta.87-x86_64-linux.sha256
tar -xzf jarvis-0.3.0-beta.87-x86_64-linux.tar.gz
cd jarvis-0.3.0-beta.87-x86_64-linux
./install.sh
export PATH="$HOME/.local/bin:$PATH"
jarvis setup
jarvis doctor --section setup
jarvis tui

Release page →

Community · Arch / CachyOS

AUR (jarvis-bin)

Binary package from the same release asset. PKGBUILD lives in the repo under packaging/aur/jarvis-bin until published to the AUR.

# After AUR publish:
yay -S jarvis-bin
# Or local:
cd packaging/aur/jarvis-bin && makepkg -si
jarvis doctor

Optional: install podman for agent isolation (recommended).

Enterprise · hardened

Podman EE Recommended

Non-root, hardened, minimal attack surface. Runs harnessd with Glass on port 7777 (fleet, runs, approvals — bearer-token auth).

cd jarvis   # git clone of libertaria/Jarvis
./packaging/containers/build-ee.sh v0.3.0-beta.87

export JARVIS_BEARER_TOKEN=$(openssl rand -hex 24)
podman run -d --name jarvis-ee -p 7777:7777 \
  -e JARVIS_BEARER_TOKEN -e JARVIS_UTCP_PORT=7777 \
  -v jarvis-ee-data:/var/lib/jarvis \
  localhost/jarvis-ee:v0.3.0-beta.87

curl -s http://127.0.0.1:7777/health

Then open Glass Settings with base http://127.0.0.1:7777 and the same token.

Community · Debian container

Podman CE

Debian Trixie base, free forever (LSL-1.0). For daemon-only hosts that don't need Glass or the commercial EE posture.

./packaging/containers/build.sh v0.3.0-beta.87

podman run -d --name jarvis-ce \
  -v jarvis-ce-data:/var/lib/jarvis \
  localhost/jarvis-ce:v0.3.0-beta.87
podman logs -f jarvis-ce

Image labels declare edition=ce, license-model=free-forever.

Enterprise · Debian

Podman EE (Debian)

Same hardened EE artifact, Debian Trixie base. Use when your registry prefers a Debian line.

podman build -f packaging/containers/Containerfile.ee \
  --build-arg USE_LOCAL=1 \
  --build-arg JARVIS_VERSION=v0.3.0-beta.87 \
  -t localhost/jarvis-ee-debian:v0.3.0-beta.87 .

export JARVIS_BEARER_TOKEN=$(openssl rand -hex 24)
podman compose -f packaging/containers/compose.ee.yml up -d
curl -s http://127.0.0.1:7777/health

Details: packaging/containers/README.md.

Sovereign distribution

Prebuilt via pkg.jarvis-glass.app

Skip the local build — pull a prebuilt container image straight from the sovereign R2 distribution paywall (jarvis-dist). Same artifacts as the local build, served by a Cloudflare Worker with KV-licensed EE gating and a per-edition counter. Three editions, one tarball each.

# Community — free forever, no token
curl -fsSL https://pkg.jarvis-glass.app/ce/SHA256SUMS
podman load -i <(curl -fsSL \\
  https://pkg.jarvis-glass.app/ce/jarvis-ce_latest_linux_amd64.tar.gz)

# Enterprise — token-gated when EE_REQUIRE_TOKEN=true
curl -fsSL "https://pkg.jarvis-glass.app/ee/jarvis-ee_latest_linux_amd64.tar.gz?token=$JARVIS_LICENSE" \\
  | gunzip | podman load

# Enterprise Debian fallback
podman load -i <(curl -fsSL \\
  https://pkg.jarvis-glass.app/ee-debian/jarvis-ee-debian_latest_linux_amd64.tar.gz)

The sovereign VPS at sovereign-forge-2 shields public download traffic: push-to-forge.sh stays the operator-side path; everything else goes through the Worker. Stats (gated by bearer) at https://pkg.jarvis-glass.app/stats. See jarvis-dist/README.md for license tokens + the EE paywall mechanism.

Sovereign forge · registry

Pull from the forge registry

Once published, every tagged JARVIS image is reachable from any container on the sovereign forge's host network via 127.0.0.1:5000. Containers outside the forge can pull through the SSH tunnel or a forwarding reverse-proxy.

# On a forge-resident container (host network or bridge with :5000 accessible)
podman pull 127.0.0.1:5000/jarvis-ce:v0.3.0-beta.87
podman pull 127.0.0.1:5000/jarvis-ee:v0.3.0-beta.87

# From outside, via SSH tunnel
ssh -L 5000:127.0.0.1:5000 -p 30022 root@178.105.157.200 -N &
podman pull --tls-verify=false 127.0.0.1:5000/jarvis-ee:latest

Registry catalog (anonymous) returns 401, authed operators see the full list. Credentials live in ~/.config/jarvis/forge-auth.env on operator workstations; CI gets them via Forgejo Actions secrets.

The Community Edition binary and container are released under LSL-1.0 — free forever, no telemetry, no usage caps. The Enterprise Edition runs as a Public Beta until 1.0; commercial licensing terms will land with the 1.0 cutover. Labels on every image declare its edition, posture, and license model.

podman image inspect localhost/jarvis-ce:v0.3.0-beta.87 \
  --format '{{json .Config.Labels}}' | jq
{
  "org.opencontainers.image.licenses": "LSL-1.0",
  "org.opencontainers.image.vendor":   "Sovereign Society",
  "org.sovereign-society.jarvis.edition":        "community",
  "org.sovereign-society.jarvis.license-model":  "free-forever",
  ...
}

podman image inspect localhost/jarvis-ee:v0.3.0-beta.87 \
  --format '{{json .Config.Labels}}' | jq
{
  "org.opencontainers.image.licenses": "LicenseRef-Jarvis-EE-1.0",
  "org.opencontainers.image.vendor":   "Sovereign Society",
  "org.sovereign-society.jarvis.edition":        "enterprise",
  "org.sovereign-society.jarvis.license-model":  "commercial-public-beta",
  "org.sovereign-society.jarvis.posture":        "non-root-hardened",
  ...
}

Steer. Observe. Let it run.

  • jarvis doctor — health, sandbox mode, missing setup
  • jarvis tui — Cockpit (local CE primary UI)
  • Glass PWA — /app opens in Preview (simulated); Settings connects your harnessd for live glass
  • jarvis sandbox health — Podman path for agent work
  • Security — project-only work by default; see isolation

Beta track: six-week production-ready lane. Read known issues before filing bugs on Forgejo. Full GA scope (chat platforms, multi-tenant SaaS) is intentionally later.