Advanced Deployment
Use the one-line installer in the README for normal local use. This page is for manual Docker, production-style, and multi-service deployments.
Manual Local Docker
export PRAETOR_SESSION_SECRET="$(python -c 'import secrets; print(secrets.token_urlsafe(32))')"
export PRAETOR_SETUP_TOKEN="$(python -c 'import secrets; print(secrets.token_urlsafe(32))')"
docker compose -f compose.app.yaml up --build
Open:
http://127.0.0.1:9741/app/praetor?setup_token=$PRAETOR_SETUP_TOKENhttp://127.0.0.1:9741/m/briefing
Reference:
Production-Style Monolithic Docker
Use Docker secrets or _FILE environment variables for real secrets.
docker compose -f compose.app.yaml -f compose.app.production.yaml up --build -d
Multi-Service Stack
docker compose -f compose.yaml up --build
Open:
- http://127.0.0.1:3000/app/praetor
- http://127.0.0.1:3000/office
Production overlay:
docker compose -f compose.yaml -f compose.production.yaml up --build -d
Host Executor Bridge
Praetor can call host-side tools such as Codex or Claude Code through praetor-execd. Keep the bridge outside Docker so the container does not need direct access to host credentials or the Docker socket.
Decision rule:
- Use API mode when you want the simplest Docker install. No host bridge is required.
- Use host bridge mode when you want Praetor agents to use an existing Codex or Claude Code subscription. Log into those tools on the host, not inside Docker, then run
scripts/praetor.sh configure-executor codexorscripts/praetor.sh configure-executor claude_code. - Use in-Docker Codex login only for an intentionally self-contained advanced deployment where you accept that Codex credentials and browser/session state live inside the container environment.
Bridge mode keeps the normal local install simple: Docker runs Praetor, the host keeps executor credentials, and workspace paths are mapped through the bridge config.
See: