Install the gate
The gate runs on a Linux server with KVM. One command installs it; a second one connects it to your organization.
Requirements
Section titled “Requirements”- Linux x86_64 with KVM: a bare-metal server, or a VM with nested virtualization.
- Ubuntu 24.04 or later, or Debian 13 or later.
- About 3.5 GB free disk space while installing, 1.5 GB after.
- Outbound HTTPS to your Noset server, to GitHub and to the npm registry.
Install and connect
Section titled “Install and connect”-
Install the gate. Run it with
sudofrom the user the gate should run as:Terminal window curl -fsSL https://get.noset.ai/install.sh | sudo bash -
Connect it to your organization:
Terminal window noset loginTerminal window noset login --server https://noset.example.comBehind a proxy that opens TLS, add
--ca-cert ca.pem. -
Open the link it prints, on your laptop or phone. Check that the code matches the terminal, then name the gate and click Connect server.
The web app shows the same two commands, with your server’s address, under Gates › Connect a server.
What the installer does
Section titled “What the installer does”The script is short and readable: get.noset.ai/install.sh. It
- checks the machine (root, x86_64, KVM, systemd, the distribution, disk space);
- installs
virtiofsd,uidmapandzstdfrom your distribution; - downloads
nosetand the sandbox’s root file system from Noset, Cloud Hypervisor and the guest kernel from GitHub, and Claude Code from npm, and checks each file against its SHA-256 before using it; - builds the tools disk with Claude Code on your server;
- adds your user to the
kvmgroup and startsnoset.service, which waits fornoset login.
Run it again to update. Your gate’s keys, login and evidence stay.
Connect many servers at once
Section titled “Connect many servers at once”For CI or a fleet, create a token in the web app (Gates › Connect a server › With a token) and run on each server:
curl -fsSL https://get.noset.ai/install.sh | sudo bashnoset login --server https://noset.example.com --token nst_en_…A token works for the time and number of servers you choose, and each server gets its own key.
Run your first agent
Section titled “Run your first agent”cd ~/projectnoset run --credential ANTHROPIC_API_KEY -- claudeThe agent runs in the sandbox with your project folder at /workspace. Its API key stays in the gate; the agent only sees a placeholder.