fleet — let your coding agent use every machine you have
Claude Code, Codex and Gemini see one machine: the one they run on.
fleet shows them all of yours — every GPU, how much is free, and how to get there.
The problem
Ask your agent to train a model and it starts on your laptop — while a 4090 sits idle across the room and a rented A100 bills you by the hour. It cannot use what it cannot see.
- Your agent is stuck on one machine. It has no idea your other boxes exist.
- Finding a free GPU is manual. SSH into five hosts, run
nvidia-smi, compare in your head. - Handing it a server means pasting credentials into the chat, and hoping.
Install once, then just talk to your agent
On the machine you work from:
curl -LsSf https://raw.githubusercontent.com/lion-zhang/fleet/main/install.sh | sh
Windows: powershell -ExecutionPolicy ByPass -c "irm https://raw.githubusercontent.com/lion-zhang/fleet/main/install.ps1 | iex"
That is the whole setup. This machine becomes your fleet's center, and every supported agent installed on it learns fleet. From here on you say what you want in plain words — no commands to remember. When something is missing, the agent asks (illustrative):
You: add my new GPU server
Agent: Sure — how do you usually connect to it? An SSH command like
ssh -p 40001 root@1.2.3.4is all I need.You:
ssh ubuntu@10.0.0.7Agent: Added as
gpu-box: 2× RTX 4090, both idle, 46 GB free. It's ready to use.
You: train
train.pyon whatever has a free 24 GB cardAgent:
rtx4090has 23.1 GB free and an idle GPU;a100-spotis free too but costs $1.89/hr. Starting onrtx4090, logging totrain.log.
| You say | What happens |
|---|---|
| "what's free right now?" | every machine checked, the free ones listed |
| "find me a box with a 24 GB card" | machines matched by what they have, not by name |
| "run the tests on the Linux box" | run there, results brought back |
| "what's costing me money?" | idle paid rentals flagged, with their hourly price |
| "let the laptop reach the NAS" | access granted, applied at once |
| "add a machine without typing its password" | a one-time line to paste there; it joins by itself |
No hostnames, keys or passwords go into the conversation, and anything irreversible waits for your yes.
Every machine besides the center is a member. A member needs nothing installed — just sshd. For machines where you also want to run fleet, or that you would rather not type a password for, the agent gives you an invite line: pasted there, it installs fleet and joins by itself.
Already in your agent? Install from there
| Agent | Install |
|---|---|
| Claude Code | /plugin marketplace add lion-zhang/fleet then /plugin install fleet@fleet |
| Codex | codex plugin marketplace add lion-zhang/fleet then codex plugin add fleet@fleet |
| Gemini CLI | gemini extensions install https://github.com/lion-zhang/fleet |
| GitHub Copilot CLI | copilot plugin marketplace add lion-zhang/fleet then copilot plugin install fleet@fleet |
| Cursor | |
| VS Code | |
| Claude Desktop | open fleet.mcpb from the latest release |
Plus OpenCode, Amp, Windsurf, Cline, Zed, Qwen Code, Goose, Kiro, Hermes — 35+ agents in all: every agent →
On a machine in no fleet yet, these make it a center on first use, like the installer. For a member, paste its invite line first.
Built to be safe
- Nothing to install on your machines. fleet probes with one script over one SSH connection — Linux, macOS or Windows. A NAS or a fresh rental works as it is.
- Keys, not passwords. A password, if needed at all, is typed once by you. Nothing that could be stolen is stored, and the agent never sees a credential.
- Access you control. The center decides which machine may reach which, and a revoke
is pushed at once.
fleet access gpu-box --allow laptop,--denyto take it back. - The agent asks, not guesses. It is told to ask which machine you mean, and to leave irreversible commands to you.
Prefer the command line?
Everything the agent does is a plain fleet command, for when you want to drive it
yourself:
fleet ls # every machine, with what is free right now
fleet ls --tag cuda --tag vram-24g # by capability: NVIDIA, a card of 24 GB or more
fleet top # live view, like htop for the whole fleet
fleet show gpu-box # one machine in detail: GPU processes, services, disks
fleet ssh gpu-box -- nvidia-smi # run something there
fleet add "ssh ubuntu@10.0.0.7" # add a machine; fleet invite NAME for a join line
fleet access nas --allow laptop # let one machine reach another
Rentals from vast.ai, RunPod or Lambda show their price (fleet edit a100 --cost 1.89),
the fleet's burn rate, and an alert when a paid machine sits idle. On Tailscale, ZeroTier
or WireGuard? fleet just needs an address it can route to.
How fleet compares
fleet is about the machines you already have. It complements tools that launch new ones.
ssh + nvidia-smi |
nvitop / gpustat | SkyPilot / dstack | fleet | |
|---|---|---|---|---|
| All your machines in one view | ✗ | ✗ one machine | ✓ the ones it manages | ✓ |
| Built for coding agents (skill / MCP) | ✗ | ✗ | partly | ✓ |
| Nothing installed on target machines | ✓ | ✗ | ✗ | ✓ |
| Manages SSH access between machines | ✗ | ✗ | for its own clusters | ✓ |
| Launches new cloud VMs | ✗ | ✗ | ✓ | ✗ |
FAQ
I use Claude Code and Codex (and more) on one machine. Does that work?
Yes — that is the normal case. fleet is installed once per machine: one command, one
inventory, one set of keys. Each agent only gets a small skill or MCP entry pointing at
it, so Claude Code, Codex, Gemini CLI and a desktop app all see the same machines, and can
use them at the same time. Install a new agent later? Run fleet setup (or ask an agent
that already has fleet to do it).
What does my agent actually get?
Agents with a shell (Claude Code, Codex, Gemini CLI, Copilot CLI, OpenCode, …) get a
skill — text that tells them the fleet commands; it costs nothing until a task needs a
machine. Apps that cannot run commands (Claude Desktop, Cursor, VS Code, …) get an MCP
server that runs the same commands for them. The installer sets up the supported agents
you have; docs/agents.md has the details for each.
Does it work behind NAT, or across sites?
The center needs an address it can route to: a public IP, a LAN, or an overlay such as
Tailscale. A machine the center cannot dial can still join with the fleet invite line
and report in; granting access to it waits until the center can reach it.
What if the center is off?
Normal — it can be a laptop that is closed half the day. Everything already granted keeps
working; only changes wait for it. Move the role with fleet center NAME.
Windows?
Yes, both ways. A Windows machine works as a target with OpenSSH Server and nothing else,
and fleet runs on Windows too, center included: interactive fleet ssh, fleet top and
the background service all work there. See Windows.
Learn more
- Getting started — the full walkthrough, every command
- Every agent — install commands and config for 35+ agents
- Design — one core per machine, a skill per agent, MCP for the rest; and access — how access is granted, signed and revoked
Status: v0.5. The test suite runs on Linux, macOS and Windows, and every command is run end to end on a real machine of each OS in CI — from a script, as an agent runs it, and at a real terminal, as you do. Multi-machine fleets (key, password, invite, handover) are tested on Linux machines built from scratch.
Issues and pull requests are welcome — uv run pytest -q runs the tests. If fleet saved
you a GPU-hour, a ⭐ helps other people find it.
Metadata
Release files for agents-fleet 0.5.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agents_fleet-0.5.0.tar.gz | 521.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agents_fleet-0.5.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 749.5 kB
Release files / agents_fleet-0.5.0.tar.gz
| Download URL | agents_fleet-0.5.0.tar.gz |
|---|---|
| Size | 521.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5f6af8b6d2fe615516d5815cb8dc4c0aabdeb3fc6ad3b088aaf032464dda33d6
|
|
BLAKE2b-256 checksum How to use checksums |
069812967e16bacbec568fa3787fd7ff20c09498eff844f60d640b75547b3cd9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency logRelease files / agents_fleet-0.5.0-py3-none-any.whl
| Download URL | agents_fleet-0.5.0-py3-none-any.whl |
|---|---|
| Size | 228.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5ac7412eeafc7363f44a0aeb7c07e9085cd6681e22ccf3b01918d36fc9eadbca
|
|
BLAKE2b-256 checksum How to use checksums |
aa3b1e940df6d6268d3c63c93e9a48644f943d867d6b794fff4ef9ab93d37ba4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency log