Overview

Product

An AI coding agent you run your way — on infrastructure you choose, configure, and control.

The CLI, v1.18.42

What's in the CLI today

Any model provider, including local ones

Inherited from opencode: point it at the provider you choose, or at a local model for air-gapped use.

Four modes

build, plan (no edits), research (Markdown notes, no code changes) and dev-cycle, which runs discover, architect, plan, build and verify with a human approval gate between phases.

Data-residency policy

Block model providers outside the jurisdictions you allow, before any request is made. Enforced for sessions from v1.18.39; from v1.18.41 an EU claim holds only for the provider’s own API hosts, and residency.endpoints declares where your own endpoints run.

An audit log you can verify

One local, hash-chained log of model calls, tool runs, permission decisions, installs and policy refusals, never prompts or file contents. lunos audit verify checks it, and events can be forwarded to syslog.

Organisation policy

A managed.json only administrators can write, or a macOS MDM profile, locks settings developers can’t change. No server is involved; lunos debug config --sources shows which layer set each key.

Offline mode

LUNOS_OFFLINE=1 turns off every outbound call Lunos makes on its own behalf, leaving only the endpoints you configured. Offline install bundles cover machines with no internet access.

Background subagents

An opt-in setting. /tasks lists every background job with its agent, model, status and elapsed time, and lets you open or cancel it.

A model per subagent

Set a model per subagent, inherit the main one, or let the main agent pick per task from a list you allow. Each choice is checked against the residency policy.

Skills, hooks and Claude Code compatibility

SKILL.md skills can restrict the agent with allowed-tools. Config hooks run commands on tool and session events. Claude Code subagents in .claude/agents are picked up as they are.

A reviewed, built-in marketplace

Install plugins and MCP servers from lunos-community with one command, after a preview of what will run and which config file changes. A verified entry installs only the reviewed version; a community entry needs --allow-unreviewed.

Long-term memory, off by default

Turn it on and the agent keeps facts across sessions, asking you before it keeps each one by default. lunos memory lists, searches, forgets and exports them. Needs uv and Python 3.10–3.13; the first start downloads its packages and a local embedding model.

Artifacts that stay in your repo

Plans, research notes and dev-cycle records are Markdown files you commit; /artifacts finds and opens them, and /export writes a session to a local file.

Sharing off by default

Session sharing uploads nothing unless you turn it on, and share uploads are checked against the residency policy like model calls.

Updates you choose

Update checks track Lunos, not upstream opencode. A new release is announced, never installed silently unless you opt in; /upgrade installs it.

Early software: checksums and the SBOM are Sigstore-signed, but binaries are not OS code-signed yet, and feature parity with other agents is not claimed. See the changelog for what shipped when, and Install to try it.

Phase 1

What ships today

Phase 1 is this marketing site plus a minimal contact backend — lunos.tech for the public-facing content and api.lunos.tech for a small, independently deployable API. See the feature parity table for how Lunos compares to Claude Code and opencode.

Audiences

Who it's for

Public sector

EU public-sector integrators and GovTech/civic-tech developers.

Parity evaluators

opencode contributors and Claude Code users evaluating Lunos for parity features.

Regulated enterprise

EU regulated-enterprise engineering teams for whom US-hosted tooling is a procurement blocker.

Developers who want control

Any developer who would rather own their toolchain than rent it — run it locally, point it at the models you pick, and change what you don't like.