Praetor Install Checklist
Status: beta readiness checklist.
Use this checklist before publishing a release candidate or asking users to install Praetor.
Local Docker smoke path
cp .env.example .env
mkdir -p workspace data config secrets
python -c 'import secrets; print(secrets.token_urlsafe(32))' > secrets/praetor_session_secret.txt
python -c 'import secrets; print(secrets.token_urlsafe(32))' > secrets/praetor_setup_token.txt
python -c 'import secrets; print(secrets.token_urlsafe(32))' > secrets/praetor_bridge_token.txt
touch secrets/openai_api_key.txt secrets/anthropic_api_key.txt
docker compose -f compose.app.yaml -f compose.app.production.yaml up --build
Then open:
http://127.0.0.1:9741/app/praetor
Expected result:
- healthcheck passes
- onboarding requires setup token
- onboarding completion page shows App URL, workspace path, doctor command, backup command, and executor setup command
- workspace selector defaults to a user-visible local folder and explains that company files stay inside the workspace root
- the selected workspace can be opened directly from the host and contains owner-visible company folders:
Projects/,Missions/,Wiki/,Decisions/, andArchive/ - File System Steward copy is visible in onboarding or workspace docs: it owns naming hygiene, placement guidance, missing-file checks, and archive suggestions
- onboarding previews the initial AI company org chart and approval boundaries
- owner login is created
- logout/login works
- mission creation works
- generated workspace files are owned by the local user or container user and are not world-readable
- Docker install path is clear: API mode runs fully in Docker; subscription executor mode uses the host bridge for Codex or Claude Code
- Executor setup is clear: do not log into Codex or Claude Code inside Docker for normal local use; use
scripts/praetor.sh configure-executor codexorscripts/praetor.sh configure-executor claude_codeon the host so Praetor can call the already-authenticated local CLI throughpraetor-execd
First-run decision checks
Confirm that first-run setup makes these decisions explicit without requiring
the owner to understand internal services:
- Install mode: Docker quickstart is the default local app path; source/Pixi is labeled as the developer path.
- Workspace root: owner chooses or accepts one visible local folder, and Praetor keeps all company files inside it.
- AI runtime: dry-run demo works without external credentials; API providers require keys; Codex subscription use requires the host bridge.
- Codex bridge boundary: Codex login stays on the host. The container only talks to
praetor-execdon loopback with a bearer token. - Recovery commands: completion page and README point to
doctor,validate-install,backup,restore, andconfigure-executor.
Pixi smoke path
pixi install
pixi run check
pixi run docs-site
npm --prefix apps/web run typecheck
npm --prefix apps/web run build
pixi run app-auth-smoke
pixi run app-security-smoke
pixi run app-api-smoke
pixi run app-fallback-smoke
pixi run stack-smoke
pixi run app-smoke
pixi run packaging-smoke
pixi run release-readiness
Expected result:
- all tasks exit successfully
public/index.htmlis generated- local state is not committed
pixi run packaging-smokepasses and confirms installer scripts, validate-install output, Docker compose config, and backup/restore flowdocs/RELEASE_READINESS_REPORT.mdis regenerated and shows all automated gates passing
Release candidate checks
README.mdquickstart is accurate.SECURITY.mdcontact path is accurate.- Praetor public security review has no unresolved blocker for the intended release mode.
- Praetor privacy boundaries matches current behavior.
- GitHub Actions are green on
main. - OpenSSF Scorecard completes successfully.
- GitHub Pages deploys successfully.
- Branch protection required checks match the current workflow names.
Release command
git tag v0.1.0-rc.1
git push origin v0.1.0-rc.1
The release workflow creates the GitHub release and source archive.