Run it wherever you choose
Self-hosted, cloud-hosted, or air-gapped, with model routing built into the provider abstraction from day one — pick your infrastructure and provider, not the vendor's.
EU-sovereign · self-hostable
The AI coding agent that answers to you.
Skills, hooks, a plugin marketplace, full agentic power — running on infrastructure you choose, audit, and control.
Install guide and other ways to run it →
Why now
Self-hosted, cloud-hosted, or air-gapped, with model routing built into the provider abstraction from day one — pick your infrastructure and provider, not the vendor's.
Packaged, reusable instruction sets and lifecycle hooks around every tool call.
Discover, cache, and install community plugins straight from the CLI or the TUI — extend the agent without forking anyone's config.
A residency policy that blocks disallowed model providers before any request is made, and an audit log of every model call, tool run, permission decision and install — config a procurement officer can actually review, not a vendor's word that your data stays put.
Cool tools
The residency policy is checked when a model is resolved, before any connection, so no surface can reach a blocked provider. Every outbound call is logged by destination host, never by content.
Subagents keep working while you do. /tasks lists each one with its agent, model, status and elapsed time; Enter opens it and ctrl+d cancels it.
Give each subagent its own model, let it inherit the main one, or let the main agent pick per task from a list you allow. Every choice is checked against the residency policy before the subagent starts.
A SKILL.md can declare allowed-tools, in Claude Code's format, enforced through the permission system until the turn ends. Hook scripts receive LUNOS_AGENT and LUNOS_SKILL, so they know who is calling.
One mode runs the whole cycle: discover, architect, plan, build and verify, with a human approval gate between phases. Plans and records land as Markdown in your repo, and /artifacts finds and opens them.
Every install previews what it will run and which config file it writes, then asks. Entries carrying config substitution tokens like {file:…} are refused, so a manifest can't make your config read a local file.
A managed.json that only administrators can write, or a macOS MDM profile, locks the settings you choose. Config, environment variables, flags and in-session commands can't change them, and no server is involved. lunos debug config --sources shows which layer set each key.
Tool runs, permission decisions, installs and policy refusals go into one local, hash-chained log with model calls, never prompts or file contents. lunos audit verify checks the chain, and events can be forwarded to syslog.