Concepts
Architecture
The pillars, the process model, and what runs where.
Ant is a local-first CLI with one optional companion: a machine daemon
(ant-worker, built from cmd/agent) that a remote machine runs to accept
deploys.
┌─────────────────────────────┐ ┌─────────────────────────────┐
│ Your machine (nest) │ │ Remote machine (nest) │
│ │ iroh │ │
│ ant CLI ──▶ Docker │═══════▶│ ant-worker ──▶ Docker │
│ │ └──▶ Caddy │ mutual │ │
│ ant ui │ TLS │ │
└─────────────────────────────┘ └─────────────────────────────┘
What runs where
| Component | Runs | Purpose |
|---|---|---|
ant | Your machine | Build, deploy, manage, serve the dashboard (ant ui, a command group) |
ant-worker | A remote machine | Accept images and build contexts, build/run containers, apply compose and routes |
| Docker | Both | Build and run images |
| Caddy | Your machine (optional); a remote machine (required) | Route domains to containers |
Local first
The local loop (ant haul → ant trail deploy local) needs only Docker and
the ant binary. Caddy and the optional builders are detected by
ant nest tools and reported, never assumed. Nothing about the local loop
requires an account, a server, or a network.
Build, Collab, Deploy
- Build turns a project into an image. The builder is chosen by
deploy.buildinant.yaml. - Collab is identity and access: your portable account key, the roster of users on each machine, and the groups that divide a codebase.
- Deploy runs the image, locally behind Caddy, or on a remote machine over the transport.
Fail closed
The daemon is the authority. Mutual TLS authenticates the channel, but every gated RPC is also authorized against the machine's roster. With no roster and no bootstrap owner, every gated method is refused. See Security model.