FleetQ

by escapeboy

Not rated
GitHub

About

AI Agent Mission Control — 200+ MCP tools for managing agents, experiments, workflows, crews, skills, approvals, budgets, and more.

Details

Author
escapeboy
Categories
Developer Tools

Setup (Docker — connecting container to host)

The containers reach the host machine viahost.docker.internal, which is pre-configured indocker-compose.ymlviaextra_hosts: host.docker.internal:host-gateway.

ssh-keygen -t ed25519 -C "fleetq-agent@local" -f ~/.ssh/fleetq_agent_key -N ""
cat ~/.ssh/fleetq_agent_key.pub >> ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys

Navigate toCredentials → New Credential:

- Type:SSH Key
- Paste the contents of~/.ssh/fleetq_agent_key(private key)

curl -X POST http://localhost:8080/api/v1/credentials \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ -d '{ "name": "Host SSH Key", "credential_type": "ssh_key", "secret_data": {"private_key": "<contents of fleetq_agent_key>"} }'

Navigate toTools → New Tool → Built-in → SSH Remote, or via API:

curl -X POST http://localhost:8080/api/v1/tools \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ -d '{ "name": "Host SSH", "type": "built_in", "risk_level": "destructive", "transport_config": { "kind": "ssh", "host": "host.docker.internal", "port": 22, "username": "your-username", "credential_id": "<credential-id>", "allowed_commands": ](http://localhost:8000)["ls", "pwd", "whoami", "uname", "date", "df"] }, "settings": {"timeout": 30} }'

In the Agent detail page, go toToolsand assign the SSH tool. The agent will now have anssh_executefunction available during execution.

The platform enforces a multi-layer security hierarchy for bash and SSH commands:
- Platform-level— always blocked:rm -rf /,mkfs,shutdown,reboot, pipe-to-shell patterns
- Organization-level— configure inSettings → Security Policyor via thetool_bash_policyMCP tool
- Tool-levelallowed_commandswhitelist in the tool's transport config
- Project-level— additional restrictions in project settings
- Agent-level— per-agent overrides on the tool pivot

More restrictive layers always win. A command blocked at the platform level cannot be unblocked by any other layer.

Trusted host fingerprints are viewable and removable via:

- API:GET /api/v1/ssh-fingerprints/DELETE /api/v1/ssh-fingerprints/{id}
- MCP:tool_ssh_fingerprintswithlistordeleteaction

Remove a fingerprint when a host's SSH key is legitimately rotated — the next connection will re-verify via TOFU.

flowchart LR subgraph Clients["Operators & external agents"] UI["Admin UI — Livewire 4 + Alpine"] MCPCLI["MCP clients (Claude Desktop, Cursor, Codex, Claude Code)"] APIC["REST clients — /api/v1/ (Sanctum)"] SIG["Inbound signals (webhook / RSS / IMAP / Slack / Telegram)"] end UI --> WEB APIC --> API MCPCLI -->|HTTP/SSE or stdio| MCP SIG --> INGEST subgraph App["FleetQ app (Laravel 13 / PHP 8.4)"] WEB["Web routes (auth:web)"] --> DOM API["/api/v1/ — Sanctum tokens"] --> DOM MCP["AgentFleetServer — 675+ MCP tools / 62 tool groups"] --> DOM INGEST["SignalWebhookController / IngestSignalAction"] --> TRIG["TriggerRule evaluator"] TRIG --> DOM DOM["Domain layer — Agent / Crew / Experiment / Workflow / Project / Approval / Budget / Tool / Credential / Skill / Outbound"] DOM --> SM["ExperimentStateMachine (20 states)"] SM --> EVT(("ExperimentTransitioned event")) EVT --> STAGE["BaseStageJob + PlaybookExecutor"] STAGE --> GATEWAY["AI Gateway (PrismPHP) — 6-layer middleware + circuit breakers"] GATEWAY --> LLM["Providers: Anthropic / OpenAI / Google / Ollama / vLLM / Codex / Claude Code"] STAGE --> TOOLS["ToolTranslator — MCP stdio/HTTP, bash, filesystem, browser, SSH (TOFU)"] STAGE --> APPR["ApprovalRequest / HumanTask (auth:web inbox)"] STAGE --> OUT["Outbound connectors — Email / Telegram / Slack / Webhook / ntfy"] STAGE --> ARTI[("Artifact + ArtifactVersion")] DOM --> DB[("Postgres 17 + pgvector — semantic cache, UUIDv7, JSONB+GIN")] STAGE --> QUEUE[("Redis 7 — 6 Horizon queues, cache, locks")] APPR --> DB ARTI --> DB end subgraph Optional["Optional Docker profiles"] REVERB["Reverb — WebSocket live team graph"] BROWSER["browserless (Chromium)"] SEARX["searxng"] VOICE["voice-worker (LiveKit / Deepgram)"] SANDBOX["bash_sidecar (sandboxed shell)"] RELAY["fleetq-bridge relay"] JAEGER["Jaeger — OTLP traces (--profile observability)"] end App -.OTLP spans.-> JAEGER UI <-->|WebSocket| REVERB TOOLS -.->|browser tools| BROWSER TOOLS -.->|web search skill| SEARX TOOLS -.->|bash skill| SANDBOX App <-->|relay| RELAY DOM <--> VOICE

The platform is a single Laravel 13 monolith that exposes three coequal control surfaces over the same domain layer: the Livewire admin UI, a Sanctum-authenticated REST API at/api/v1/*(~175 endpoints), andAgentFleetServer— an MCP server with 675+ tools across 62 tool groups served over both HTTP/SSE and local stdio. Inbound signals (webhook, RSS, IMAP, Slack, Telegram, and the rest of the 20+ connectors) flow throughIngestSignalActionand theTriggerRuleevaluator into the domain layer, where theExperimentStateMachinewalks a 20-state pipeline by emittingExperimentTransitionedevents whose listeners dispatch the nextBaseStageJobonto Horizon-managed Redis queues. Stage jobs talk to LLMs through the PrismPHP-backed AI Gateway (rate-limit, budget, idempotency, semantic-cache, schema-validation, usage-tracking middleware + circuit breakers + provider fallbacks), invokeToolinstances translated to PrismPHP tool calls (MCP stdio/HTTP, built-in bash/filesystem/browser, SSH with TOFU fingerprints), parkApprovalRequest/HumanTaskrecords for the human-in-the-loop inbox, and persistArtifactversions plus deliver outbound messages over Email/Telegram/Slack/Webhook/ntfy. State and tenant data live in Postgres 17 with pgvector (semantic cache, UUIDv7 primary keys, JSONB+GIN indexes); Redis 7 carries the six Horizon queues, application cache, and pessimistic budget locks. Optional Docker Compose profiles add Reverb for the live team-graph WebSocket, browserless for browser tools, searxng for web search, a voice worker (LiveKit/Deepgram), a sandboxed bash sidecar, the fleetq-bridge relay, and Jaeger for OpenTelemetry tracing via--profile observability.

Built with Laravel 13, Livewire 4, and Tailwind CSS. Domain-driven design with 45 bounded contexts — table below shows the 17 primary domains:

make start # Start services make stop # Stop services make logs # Tail logs make update # Pull latest + migrate make test # Run tests make shell # Open app container shell
docker compose exec app php artisan tinker # REPL docker compose exec app php artisan test # Run tests docker compose exec app php artisan migrate # Run migrations

This pulls the latest code, rebuilds containers, runs migrations, and clears caches.

- Framework:Laravel 13 (PHP 8.4)
- Database:PostgreSQL 17
- Cache/Queue:Redis 7
- Frontend:Livewire 4 + Tailwind CSS 4 + Alpine.js
- AI Gateway:PrismPHP
- Queue:Laravel Horizon
- Auth:Laravel Fortify (2FA) + Sanctum (API tokens)
- Audit:spatie/laravel-activitylog
- API Docs:dedoc/scramble (OpenAPI 3.1)
- MCP:laravel/mcp (Model Context Protocol)

Contributions are welcome. Please open an issue first to discuss proposed changes.
- Fork the repository
- Create a feature branch (git checkout -b feat/my-feature)
- Make your changes and add tests
- Runphp artisan testto verify
- Submit a pull request

SeeCONTRIBUTING.mdfor coding conventions, commit style, and PR checklist.

- IssuesBug reports + feature requests
- Discussions
Ask a question or share what you built
- Changelog
What changed in each release
- Cloud version
fleetq.net(free tier, no credit card)

If FleetQ saves you time, a ⭐ helps others find it. GitHub ranks repos by star velocity.

FleetQ Community Edition is open-source software licensed under theGNU Affero General Public License v3.0.

TL;DR of AGPLv3:You can self-host, modify, and run FleetQ for free — including commercial use. If you offer FleetQ as a hosted service to others, you must open-source your modifications. Questions? Seeour AGPLv3 FAQ.

FleetQ — Open-Source AI Agent Orchestration Platform

Self-hosted mission control for AI agents.Build, run, and monitor autonomous multi-agent systems with a visual DAG builder, human-in-the-loop approvals, MCP server integration, and full audit trail. Works with Claude, GPT-4o, Gemini, Ollama, Codex, Claude Code, and any OpenAI-compatible LLM.

Keywords:AI agents · agent orchestration · MCP server · Model Context Protocol · LangGraph alternative · CrewAI alternative · n8n for AI · Claude agents · LLM workflow · autonomous agents · agent framework · AI automation · self-hosted

☁️Prefer managed?TryFleetQ Cloud— zero setup, free tier. ⭐Like the project?Give it a star on GitHub — it helps others find FleetQ.

- Why FleetQ?
-
Key Concepts
-
Screenshots
-
Features
-
Use Cases
-
How FleetQ compares
-
Quick Start
-
Authentication
-
Configuration
-
SSH Host Access
-
Architecture
-
MCP Server (675+ tools)
-
Tech Stack
-
Contributing
-
Changelog

Most agent frameworks give you a Python notebook. FleetQ gives you aproduction platform.

- 🧩675+ MCP tools across 45 domains— every feature is exposed via Model Context Protocol, so any LLM (Claude Desktop, Cursor, ChatGPT, local agents) can drive the platform programmatically. New in 1.27: web UIs for previously headless capabilities (agent sessions, release signing keys, drift & eval monitors, broadcasts, test suites, CSV import);eight outbound chat channelsas first-class drivers; theAgentic AI Flywheel(self-growing eval set + drift/production monitors);policy-governed autonomy(versioned per-agent policies + replay);cost-aware orchestrationandReturn on Cognitive Spend (ROCS)metrics.
- 🔁Visual DAG workflowswith 8 node types (agent, conditional, human-task, switch, dynamic-fork, do-while, compensation, sub-workflow) — no Python glue code.
- 👥Multi-agent crewswith coordinator/worker/reviewer roles, weighted QA scoring, and cross-validation.
- 🛡️Real-World Action governance— assistant tool calls, integration writes, and git pushes route through a per-tier risk policy (auto / ask / reject for low / medium / high). Approvals auto-execute. Audit trail attached.
- 💰Budget controlswith a real credit ledger, pessimistic locking, and auto-pause on overspend — not just token counters.
- 🧠Agent evolution— LLM analyzes execution history and proposes config changes you approve with one click.
- ⚙️BYOK + Local LLMs— Anthropic, OpenAI, Google, plus Ollama, LM Studio, vLLM, Codex, Claude Code. Zero vendor lock-in.
- 🔒Production-grade— tenant isolation, encrypted credential vault, HMAC webhooks, SSRF guards, circuit breakers, audit trail.
- 📊OpenTelemetry observability— structured error codes (gRPC-canonical), deadline propagation, distributed tracing. Jaeger UI one-command away. Per-team OTLP collector endpoints for BYO observability.
- 📈Live team graph— Cytoscape.js force-directed visualization of agents, humans, and crews. Real-time updates via Laravel Reverb WebSockets.
- 🏠Self-host or cloud— MIT-friendly AGPLv3 license, runs on Docker Compose, or use
FleetQ Cloud.

DashboardKPI overview with active experiments, success rate, budget spend, and pending approvals.

Agent Template GalleryBrowse 14 pre-built agent templates across 5 categories. Search, filter by category, and deploy with one click.

Agent LLM ConfigurationPer-agent provider and model selection with fallback chains. Supports Anthropic, OpenAI, Google, and local agents.

Agent EvolutionAI-driven agent self-improvement. Analyze execution history, propose personality and config changes, and apply with one click.

Crew ExecutionLive progress tracking during multi-agent crew execution. Each task shows its assigned skill, provider, and elapsed time.

Task OutputExpand any completed task to inspect the AI-generated output, including structured JSON responses.

Visual Workflow BuilderDAG-based workflow editor with conditional branching, human tasks, switch nodes, and dynamic forks.

Tool ManagementManage MCP servers, built-in tools, and external integrations with risk classification and per-agent assignment.

AI Assistant SidebarContext-aware AI chat embedded in every page with 28 built-in tools for querying and managing the platform.

Experiment DetailFull experiment lifecycle view with timeline, tasks, transitions, artifacts, metrics, and outbound delivery.

Settings & WebhooksGlobal platform settings, AI provider keys (BYOK), outbound connectors, and webhook configuration.

Error HandlingFailed tasks display detailed error information including provider, error type, and request IDs for debugging.

- AI Agents— role, goal, backstory, personality traits, skill assignments, per-agent provider/model fallback chains
- Agent Templates— 14 pre-built templates across 5 categories (engineering, content, business, design, research)
- Agent Evolution— LLM analyzes execution history, proposes config changes, one-click approval
- Agent Crews— Multi-agent teams with coordinator/QA/worker roles, 7 process types (sequential, parallel, hierarchical, self-claim, adversarial, fanout, chat-room), weighted QA scoring
- Pre-Execution Scout Phase— cheap LLM pre-call identifies what knowledge the agent needs → targeted semantic search instead of generic recall
- Step Budget Awareness— agent system prompt targets 80% of allowed steps for core work, reserves the rest for synthesis
- Experiment Pipeline— 20-state machine with automatic stage progression (scoring → planning → building → approval → executing → metrics → evaluating)
- Visual Workflow DAG— 8 node types (agent, conditional, human-task, switch, dynamic-fork, do-while, compensation, sub-workflow). Pre-built Web Dev Cycle template. NL → workflow generator.
- Projects— one-shot and continuous projects with cron scheduling, budget caps, milestones, overlap policies

- BYOK— bring your own keys for Anthropic (Claude), OpenAI (GPT-4o), Google (Gemini)
- Local LLMs— Ollama, LM Studio, vLLM, llama.cpp via OpenAI-compatible endpoints; 17 preset Ollama models; SSRF protection
- Local Agents— Codex and Claude Code as execution backends (auto-detected, zero cost)
- Portkey Gateway— optional drop-in that unlocks 250+ LLM providers with semantic caching and fallbacks
- RunPod GPU Integration— invoke RunPod serverless endpoints or manage full GPU pod lifecycles as skills; BYOK API key; spot pricing
- Pluggable Compute Providersgpu_computeskills backed by RunPod, Replicate, Fal.ai, Vast.ai
- AI Gateway— provider-agnostic via PrismPHP with 6-layer middleware (rate-limit, budget, idempotency, semantic-cache, schema-validation, usage-tracking), circuit breakers, fallback chains
- Semantic Cache— pgvector-backed cosine similarity (threshold 0.92) cross-team cache — cuts LLM spend on repeat prompts

- Signal connectors— 20+ drivers: webhook, RSS, IMAP, Slack, Discord, WhatsApp, GitHub, Linear, Jira, PagerDuty, Sentry, Datadog, ClearCue, Telegram, Matrix, Notion, Confluence, Screenpipe, Searxng, more
- Bug Report signals— lightweight QA pipeline with public JS widget, screenshot + console + network + action log capture, threaded comments (reporter + agent + support), agent delegation, SLA escalation
- Trigger rules— event-driven automation with condition evaluator, dry-run testing
- Multi-Channel Outbound— Email (SMTP), Webhook, ntfy plus eight chat channels as first-class drivers (Telegram, Slack, Discord, Microsoft Teams, Google Chat, Matrix, Signal, Supabase Realtime), each with a config page, rate limiting and blacklist
- Webhooks— inbound (HMAC-SHA256) + outbound (retry, event filtering)

- Approvals— inbox with SLA enforcement + escalation
- Human Tasks— embedded form schemas on workflow nodes
- Credit Ledger— per-experiment and per-project with pessimistic locking and auto-pause on overspend
- Credential Vault— encrypted external service credentials with rotation, OAuth2, expiry tracking, per-project injection
- SSH tools— TOFU (Trust On First Use) fingerprint verification, per-tool allowed-commands whitelist, multi-layer command security policy
- Audit Trail— full activity log (spatie/activitylog), searchable + filterable
- Tenant Isolation— multi-layerTeamScope+BelongsToTeam+withoutGlobalScopes()discipline

- Integrations— GitHub, Slack, Notion, Airtable, Linear, Stripe, Vercel, Netlify, generic webhook/polling with OAuth 2.0
- Autonomous Web Dev Pipeline— agents can open PRs, merge, dispatch CI workflows, create releases, trigger Vercel/Netlify/SSH deploys through MCP tools
- Website Builder— AI-generated static sites with 8 widget types, Vercel + ZIP deployment drivers, form submissions, blog/navigation/contact widgets
- Founder Mode pack— marketplace bundle of 6 persona agents (Strategist, Product Lead, Growth Hacker, Finance Advisor, Ops Manager, Risk Officer), 20 framework skills (RICE, SPIN, BANT, MEDDIC, OKRs, Shape Up, Unit Economics, Kano, TAM-SAM-SOM, K-Factor, NPV-IRR, RACI, A/B Testing, OWASP), 5 pre-built workflows
- Marketplace— browse, publish, install shared skills, agents, workflows, and bundles with AI risk scanning

- REST API— 175+ endpoints under/api/v1/with Sanctum auth, cursor pagination, auto-generated OpenAPI 3.1 at/docs/api
- MCP Server675+ Model Context Protocol tools across 45 domains (62 tool groups)(stdio + HTTP/SSE + OAuth2/PKCE)
- Real-World Action governanceActionProposalflow gates assistant tool calls, integration writes, and git pushes through a per-tier risk policy with auto-execute on approval
- Public discovery endpointGET /.well-known/fleetqreturns a config-gated capability manifest so external AI tools can auto-configure
- Live team graph/team-graphpage with real-time updates via Laravel Reverb WebSockets
- Structured MCP errors— canonical gRPC-style error codes (UNAVAILABLE,PERMISSION_DENIED,RESOURCE_EXHAUSTED,DEADLINE_EXCEEDED,INVALID_ARGUMENT,FAILED_PRECONDITION,NOT_FOUND,INTERNAL) with retryable hints — agents know when to retry vs. fail fast
- Per-tool deadlines— optionaldeadline_msparameter on every MCP tool; agents can bound wall-clock time per call
- OpenTelemetry tracing— OTLP HTTP exporter, Jaeger all-in-one viadocker compose --profile observability up, spans for MCP tool → AI gateway → LLM provider
- Tool Management— MCP servers (stdio/HTTP), built-in tools (bash/filesystem/browser), risk classification, per-agent assignment
- MCP client compatibility— Claude Desktop, Claude.ai, ChatGPT Apps, Cursor, Codex, Claude Code, Gemini CLI, any OAuth2 client

- Queue Management— Laravel Horizon with 6 priority queues and auto-scaling
- Testing— regression test suites for agent outputs with automated evaluation
- Per-Call Working Directory— local/bridge agents can operate in a configured working directory per-agent, isolated project contexts

FleetQ is built for teams running AI agents in production, not toy demos.

- Autonomous dev pipelines— agent opens PR → CI runs → reviewer agent approves → merge → deploy. Human approves only on risk signals.
- Customer support triage— bug report widget → agent extracts reproduction steps from console/network log → experiment runs → notifies reporter with fix or agent-generated workaround.
- Multi-agent research— crew of Strategist + Researcher + Writer with QA reviewer. Each step weighted by domain rubric.
- Scheduled content ops— continuous project runs daily, each run executes a DAG: draft → review → SEO-check → publish → schedule social.
- Incident response— PagerDuty/Sentry signal → trigger rule → diagnosis agent → human approval on runbook action → Slack notify.
- GPU workloads— agent callsgpu_computeskill on RunPod serverless (Whisper, FLUX, Bark) as part of a larger workflow, with cost accounting.
- Local-first agent dev— Ollama + Codex + Claude Code auto-detected, zero API cost for prototyping; switch to cloud providers for production.
- Bring FleetQ into Claude— expose your internal data + tools as MCP server, Claude Desktop/ChatGPT/Cursor can drive the platform programmatically.

TL;DR — if you're building production agent systems with LLMs and want visual workflows + MCP + human oversight, FleetQ is the only platform that bundles all of it.

git clone https://github.com/escapeboy/agent-fleet-o.git cd agent-fleet make install

- Copy.env.exampleto.env
- Build and start all Docker services
- Run the interactive setup wizard (database, admin account, LLM provider)

Visithttp://localhost:8080when complete.

Requirements: PHP 8.4+, PostgreSQL 17+, Redis 7+, Node.js 20+, Composer

git clone https://github.com/escapeboy/agent-fleet-o.git cd agent-fleet composer install npm install && npm run build cp .env.example .env # Edit .env — set DB_HOST, DB_DATABASE, DB_USERNAME, DB_PASSWORD, REDIS_HOST php artisan key:generate php artisan migrate php artisan horizon & php artisan serve

Then openhttp://localhost:8000in your browser. The setup page will guide you through creating your admin account.

Alternative:Runphp artisan app:installfor an interactive CLI setup wizard that also seeds default agents and skills.

- No email verification— the self-hosted edition skips email verification entirely. Accounts are active immediately on registration.
- Single user— all registered users join the default workspace automatically.

If you're running FleetQ locally on your own machine and don't want to enter a password on every visit, setAPP_AUTH_BYPASS=truein.env:

APP_AUTH_BYPASS=true # Auto-login as first user APP_ENV=local # Required — bypass is disabled in production

With bypass enabled, the app logs you in automatically on every request. A logout link is still shown but you'll be logged back in on the next page load — this is intentional.

Warning:Never setAPP_AUTH_BYPASS=trueon a server accessible from the internet.

All configuration is in.env. Key variables:

# Database (PostgreSQL required) DB_CONNECTION=pgsql DB_HOST=postgres DB_DATABASE=agent_fleet # Redis (queues, cache, sessions, locks) REDIS_HOST=redis REDIS_DB=0 # Queues REDIS_CACHE_DB=1 # Cache REDIS_LOCK_DB=2 # Locks # LLM Providers -- at least one required for AI features ANTHROPIC_API_KEY= OPENAI_API_KEY= GOOGLE_AI_API_KEY= # Auth bypass -- local no-password mode (never use in production) APP_AUTH_BYPASS=false

Additional LLM keys can be configured inSettings > AI Provider Keysafter login.

To use local models (Ollama, LM Studio, vLLM):

LOCAL_LLM_ENABLED=true LOCAL_LLM_SSRF_PROTECTION=false # set false if Ollama is on a LAN IP (192.168.x.x) LOCAL_LLM_TIMEOUT=180

Then configure endpoints inSettings > Local LLM Endpoints.

Agents can execute commands on the host machine (or any remote server) via SSH using the built-in SSH tool type. This is useful for running local scripts, interacting with the filesystem, or orchestrating host-level processes from an agent.
- The platform stores SSH private keys encrypted in the Credential vault.
- An SSH Tool is configured withhost,port,username,credential_id, and an optionalallowed_commandswhitelist.
- On the first connection to a host, the server's public key fingerprint is stored viaTOFU(Trust On First Use). Subsequent connections verify the fingerprint — a mismatch raises an error to prevent MITM attacks.
- Manage trusted fingerprints viaSettings > SSH Fingerprintsor thetool_ssh_fingerprintsMCP tool.

Setup (Docker — connecting container to host)

The containers reach the host machine viahost.docker.internal, which is pre-configured indocker-compose.ymlviaextra_hosts: host.docker.internal:host-gateway.

ssh-keygen -t ed25519 -C "fleetq-agent@local" -f ~/.ssh/fleetq_agent_key -N ""
cat ~/.ssh/fleetq_agent_key.pub >> ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys

Navigate toCredentials → New Credential:

- Type:SSH Key
- Paste the contents of~/.ssh/fleetq_agent_key(private key)

curl -X POST http://localhost:8080/api/v1/credentials \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ -d '{ "name": "Host SSH Key", "credential_type": "ssh_key", "secret_data": {"private_key": "<contents of fleetq_agent_key>"} }'

Navigate toTools → New Tool → Built-in → SSH Remote, or via API:

curl -X POST http://localhost:8080/api/v1/tools \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ -d '{ "name": "Host SSH", "type": "built_in", "risk_level": "destructive", "transport_config": { "kind": "ssh", "host": "host.docker.internal", "port": 22, "username": "your-username", "credential_id": "<credential-id>", "allowed_commands": ["ls", "pwd", "whoami", "uname", "date", "df"] }, "settings": {"timeout": 30} }'

In the Agent detail page, go toToolsand assign the SSH tool. The agent will now have anssh_executefunction available during execution.

The platform enforces a multi-layer security hierarchy for bash and SSH commands:
- Platform-level— always blocked:rm -rf /,mkfs,shutdown,reboot, pipe-to-shell patterns
- Organization-level— configure inSettings → Security Policyor via thetool_bash_policyMCP tool
- Tool-levelallowed_commandswhitelist in the tool's transport config
- Project-level— additional restrictions in project settings
- Agent-level— per-agent overrides on the tool pivot

More restrictive layers always win. A command blocked at the platform level cannot be unblocked by any other layer.

Trusted host fingerprints are viewable and removable via:

- API:GET /api/v1/ssh-fingerprints/DELETE /api/v1/ssh-fingerprints/{id}
- MCP:tool_ssh_fingerprintswithlistordeleteaction

Remove a fingerprint when a host's SSH key is legitimately rotated — the next connection will re-verify via TOFU.

flowchart LR subgraph Clients["Operators & external agents"] UI["Admin UI — Livewire 4 + Alpine"] MCPCLI["MCP clients (Claude Desktop, Cursor, Codex, Claude Code)"] APIC["REST clients — /api/v1/ (Sanctum)"] SIG["Inbound signals (webhook / RSS / IMAP / Slack / Telegram)"] end UI --> WEB APIC --> API MCPCLI -->|HTTP/SSE or stdio| MCP SIG --> INGEST subgraph App["FleetQ app (Laravel 13 / PHP 8.4)"] WEB["Web routes (auth:web)"] --> DOM API["/api/v1/ — Sanctum tokens"] --> DOM MCP["AgentFleetServer — 675+ MCP tools / 62 tool groups"] --> DOM INGEST["SignalWebhookController / IngestSignalAction"] --> TRIG["TriggerRule evaluator"] TRIG --> DOM DOM["Domain layer — Agent / Crew / Experiment / Workflow / Project / Approval / Budget / Tool / Credential / Skill / Outbound"] DOM --> SM["ExperimentStateMachine (20 states)"] SM --> EVT(("ExperimentTransitioned event")) EVT --> STAGE["BaseStageJob + PlaybookExecutor"] STAGE --> GATEWAY["AI Gateway (PrismPHP) — 6-layer middleware + circuit breakers"] GATEWAY --> LLM["Providers: Anthropic / OpenAI / Google / Ollama / vLLM / Codex / Claude Code"] STAGE --> TOOLS["ToolTranslator — MCP stdio/HTTP, bash, filesystem, browser, SSH (TOFU)"] STAGE --> APPR["ApprovalRequest / HumanTask (auth:web inbox)"] STAGE --> OUT["Outbound connectors — Email / Telegram / Slack / Webhook / ntfy"] STAGE --> ARTI[("Artifact + ArtifactVersion")] DOM --> DB[("Postgres 17 + pgvector — semantic cache, UUIDv7, JSONB+GIN")] STAGE --> QUEUE[("Redis 7 — 6 Horizon queues, cache, locks")] APPR --> DB ARTI --> DB end subgraph Optional["Optional Docker profiles"] REVERB["Reverb — WebSocket live team graph"] BROWSER["browserless (Chromium)"] SEARX["searxng"] VOICE["voice-worker (LiveKit / Deepgram)"] SANDBOX["bash_sidecar (sandboxed shell)"] RELAY["fleetq-bridge relay"] JAEGER["Jaeger — OTLP traces (--profile observability)"] end App -.OTLP spans.-> JAEGER UI <-->|WebSocket| REVERB TOOLS -.->|browser tools| BROWSER TOOLS -.->|web search skill| SEARX TOOLS -.->|bash skill| SANDBOX App <-->|relay| RELAY DOM <--> VOICE

The platform is a single Laravel 13 monolith that exposes three coequal control surfaces over the same domain layer: the Livewire admin UI, a Sanctum-authenticated REST API at/api/v1/*(~175 endpoints), andAgentFleetServer— an MCP server with 675+ tools across 62 tool groups served over both HTTP/SSE and local stdio. Inbound signals (webhook, RSS, IMAP, Slack, Telegram, and the rest of the 20+ connectors) flow throughIngestSignalActionand theTriggerRuleevaluator into the domain layer, where theExperimentStateMachinewalks a 20-state pipeline by emittingExperimentTransitionedevents whose listeners dispatch the nextBaseStageJobonto Horizon-managed Redis queues. Stage jobs talk to LLMs through the PrismPHP-backed AI Gateway (rate-limit, budget, idempotency, semantic-cache, schema-validation, usage-tracking middleware + circuit breakers + provider fallbacks), invokeToolinstances translated to PrismPHP tool calls (MCP stdio/HTTP, built-in bash/filesystem/browser, SSH with TOFU fingerprints), parkApprovalRequest/HumanTaskrecords for the human-in-the-loop inbox, and persistArtifactversions plus deliver outbound messages over Email/Telegram/Slack/Webhook/ntfy. State and tenant data live in Postgres 17 with pgvector (semantic cache, UUIDv7 primary keys, JSONB+GIN indexes); Redis 7 carries the six Horizon queues, application cache, and pessimistic budget locks. Optional Docker Compose profiles add Reverb for the live team-graph WebSocket, browserless for browser tools, searxng for web search, a voice worker (LiveKit/Deepgram), a sandboxed bash sidecar, the fleetq-bridge relay, and Jaeger for OpenTelemetry tracing via--profile observability.

Built with Laravel 13, Livewire 4, and Tailwind CSS. Domain-driven design with 45 bounded contexts — table below shows the 17 primary domains:

make start # Start services make stop # Stop services make logs # Tail logs make update # Pull latest + migrate make test # Run tests make shell # Open app container shell
docker compose exec app php artisan tinker # REPL docker compose exec app php artisan test # Run tests docker compose exec app php artisan migrate # Run migrations

This pulls the latest code, rebuilds containers, runs migrations, and clears caches.

- Framework:Laravel 13 (PHP 8.4)
- Database:PostgreSQL 17
- Cache/Queue:Redis 7
- Frontend:Livewire 4 + Tailwind CSS 4 + Alpine.js
- AI Gateway:PrismPHP
- Queue:Laravel Horizon
- Auth:Laravel Fortify (2FA) + Sanctum (API tokens)
- Audit:spatie/laravel-activitylog
- API Docs:dedoc/scramble (OpenAPI 3.1)
- MCP:laravel/mcp (Model Context Protocol)

Contributions are welcome. Please open an issue first to discuss proposed changes.
- Fork the repository
- Create a feature branch (git checkout -b feat/my-feature)
- Make your changes and add tests
- Runphp artisan testto verify
- Submit a pull request

SeeCONTRIBUTING.mdfor coding conventions, commit style, and PR checklist.

- IssuesBug reports + feature requests
- Discussions
Ask a question or share what you built
- Changelog
What changed in each release
- Cloud version
fleetq.net(free tier, no credit card)

If FleetQ saves you time, a ⭐ helps others find it. GitHub ranks repos by star velocity.

FleetQ Community Edition is open-source software licensed under theGNU Affero General Public License v3.0.

TL;DR of AGPLv3:You can self-host, modify, and run FleetQ for free — including commercial use. If you offer FleetQ as a hosted service to others, you must open-source your modifications. Questions? Seeour AGPLv3 FAQ.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.