Community · power users
Linux binary
Static SQLite, no Zig required. Current beta: v0.3.0-beta.87 (x86_64, glibc).
curl -fsSL -O https://git.sovereign-society.org/libertaria/Jarvis/releases/download/v0.3.0-beta.87/jarvis-0.3.0-beta.87-x86_64-linux.tar.gz
curl -fsSL -O https://git.sovereign-society.org/libertaria/Jarvis/releases/download/v0.3.0-beta.87/jarvis-0.3.0-beta.87-x86_64-linux.sha256
sha256sum -c jarvis-0.3.0-beta.87-x86_64-linux.sha256
tar -xzf jarvis-0.3.0-beta.87-x86_64-linux.tar.gz
cd jarvis-0.3.0-beta.87-x86_64-linux
./install.sh
export PATH="$HOME/.local/bin:$PATH"
jarvis setup
jarvis doctor --section setup
jarvis tui
Release page →
Community · Arch / CachyOS
AUR (jarvis-bin)
Binary package from the same release asset. PKGBUILD lives in the repo under packaging/aur/jarvis-bin until published to the AUR.
# After AUR publish:
yay -S jarvis-bin
# Or local:
cd packaging/aur/jarvis-bin && makepkg -si
jarvis doctor
Optional: install podman for agent isolation (recommended).
Enterprise · hardened
Podman EE Recommended
Non-root, hardened, minimal attack surface. Runs harnessd with Glass on port 7777 (fleet, runs, approvals — bearer-token auth).
cd jarvis # git clone of libertaria/Jarvis
./packaging/containers/build-ee.sh v0.3.0-beta.87
export JARVIS_BEARER_TOKEN=$(openssl rand -hex 24)
podman run -d --name jarvis-ee -p 7777:7777 \
-e JARVIS_BEARER_TOKEN -e JARVIS_UTCP_PORT=7777 \
-v jarvis-ee-data:/var/lib/jarvis \
localhost/jarvis-ee:v0.3.0-beta.87
curl -s http://127.0.0.1:7777/health
Then open Glass Settings with base http://127.0.0.1:7777 and the same token.
Community · Debian container
Podman CE
Debian Trixie base, free forever (LSL-1.0). For daemon-only hosts
that don't need Glass or the commercial EE posture.
./packaging/containers/build.sh v0.3.0-beta.87
podman run -d --name jarvis-ce \
-v jarvis-ce-data:/var/lib/jarvis \
localhost/jarvis-ce:v0.3.0-beta.87
podman logs -f jarvis-ce
Image labels declare edition=ce, license-model=free-forever.
Enterprise · Debian
Podman EE (Debian)
Same hardened EE artifact, Debian Trixie base. Use when your
registry prefers a Debian line.
podman build -f packaging/containers/Containerfile.ee \
--build-arg USE_LOCAL=1 \
--build-arg JARVIS_VERSION=v0.3.0-beta.87 \
-t localhost/jarvis-ee-debian:v0.3.0-beta.87 .
export JARVIS_BEARER_TOKEN=$(openssl rand -hex 24)
podman compose -f packaging/containers/compose.ee.yml up -d
curl -s http://127.0.0.1:7777/health
Details: packaging/containers/README.md.
Sovereign distribution
Prebuilt via pkg.jarvis-glass.app
Skip the local build — pull a prebuilt container image straight
from the sovereign R2 distribution paywall
(jarvis-dist).
Same artifacts as the local build, served by a Cloudflare Worker
with KV-licensed EE gating and a per-edition counter. Three
editions, one tarball each.
# Community — free forever, no token
curl -fsSL https://pkg.jarvis-glass.app/ce/SHA256SUMS
podman load -i <(curl -fsSL \\
https://pkg.jarvis-glass.app/ce/jarvis-ce_latest_linux_amd64.tar.gz)
# Enterprise — token-gated when EE_REQUIRE_TOKEN=true
curl -fsSL "https://pkg.jarvis-glass.app/ee/jarvis-ee_latest_linux_amd64.tar.gz?token=$JARVIS_LICENSE" \\
| gunzip | podman load
# Enterprise Debian fallback
podman load -i <(curl -fsSL \\
https://pkg.jarvis-glass.app/ee-debian/jarvis-ee-debian_latest_linux_amd64.tar.gz)
The sovereign VPS at sovereign-forge-2 shields public
download traffic: push-to-forge.sh stays the
operator-side path; everything else goes through the Worker.
Stats (gated by bearer) at https://pkg.jarvis-glass.app/stats.
See jarvis-dist/README.md for license tokens + the EE paywall mechanism.
Sovereign forge · registry
Pull from the forge registry
Once published, every tagged JARVIS image is reachable from any container
on the sovereign forge's host network via 127.0.0.1:5000. Containers outside the forge can pull
through the SSH tunnel or a forwarding reverse-proxy.
# On a forge-resident container (host network or bridge with :5000 accessible)
podman pull 127.0.0.1:5000/jarvis-ce:v0.3.0-beta.87
podman pull 127.0.0.1:5000/jarvis-ee:v0.3.0-beta.87
# From outside, via SSH tunnel
ssh -L 5000:127.0.0.1:5000 -p 30022 root@178.105.157.200 -N &
podman pull --tls-verify=false 127.0.0.1:5000/jarvis-ee:latest
Registry catalog (anonymous) returns 401, authed operators see the full
list. Credentials live in ~/.config/jarvis/forge-auth.env on operator workstations; CI gets them via Forgejo Actions secrets.