Deep Dive into under the brella
Ask an AI agent to build a reporting dashboard, and getting a screenful of React is the easy part. Somebody still has to install dependencies, run the code, check the result, and keep the files when the machine stops. “Here’s your app” is doing a hell of a lot of work when what you’ve received is a code block.
Mainbrella is an open-source platform that gives agents Linux computers to work on, with an API for operating them and a dashboard for the humans supervising them. Our Builder uses those computers to turn a conversation into a frontend app. You can bring your own agent instead, run existing repositories, or operate the platform yourself.
Start with an idea, a repository, or your agent
In Build, describe a dashboard that imports a CSV and charts monthly totals. The agent writes React and TypeScript, runs tools, and shows a preview. You keep talking to change the app. Model inference runs through Cloudflare Workers AI; the project’s toolchain runs inside Linux.
If you already have code, Try helps you prepare its runtime, installation command, startup command, and port with your coding agent. Review the setup before launching. Mainbrella resolves the repository to a specific commit, so the run has a reproducible source identity. An installation failure leaves the checkout and terminal available for repair. Throwing everything away because one dependency failed is a lousy debugging workflow.
For your own agent application, use the HTTP API or JavaScript and Python SDKs. Write the input, run a program, and read its output on the same guest filesystem. You can open SSH or the browser terminal to inspect that workspace yourself. We’ve also built experimental integrations in our forks of Deep Agents, Mastra, OpenHands, Open SWE, and OpenCode. Those are fork implementations with different scopes and limitations.
Make “done” mean something
Builder doesn’t accept the model’s final message as a passing build. After installing dependencies, the platform invokes the compiler and bundler directly from the app directory:
./node_modules/.bin/tsc --noEmit &&
./node_modules/.bin/vite build
The generated package.json can’t redefine this check as a script that prints “success.” Compiler failures go back to the agent for repair, and the preview serves compiled output. The build loop makes success depend on a tool result we control.
That still doesn’t prove the dashboard adds up the CSV correctly. Try known inputs and check the totals. Mainbrella gives you running software and evidence about its build; deciding whether the software does the right thing remains an engineering job.
Keep the code when compute ends
Now ask for a date filter. Builder saves native Git history, so the first dashboard and the revised one are inspectable versions. You don’t need a GitHub account to start. R2, Cloudflare’s object storage, holds source and Git bundles; D1, its SQL database, records versions and the current head. A later build loads that work into another machine.
In this schematic, the first machine stops between requests. The saved repository carries the work into the second session. The preview and unsaved guest files have shorter lives.
You can download a source ZIP or a Git bundle that clones into an ordinary repository. The Worker assembles the bundle from storage without booting a paid guest. Downloading your own code shouldn’t require renting another computer. Our Git storage article also covers moving that history to GitHub and sending subsequent Builder commits there.
Retained source has funding and retention rules; it isn’t stored forever for free. For work outside Builder, explicitly save a workspace or export useful files before stopping. A saved workspace restores the filesystem into a fresh machine, without RAM or running processes. A chat transcript remembering a filename doesn’t preserve its bytes.
Give the app an address worth keeping
A protected preview gives you a temporary URL for the app without DNS setup. Anyone holding that URL can use it while the grant and machine remain active. That’s handy for checking a build; it’s an awkward bookmark for a dashboard you’ll open every morning.
Projects can bind a stable public endpoint to a running machine and port. Explicitly publish a replacement, and the project keeps its address. Custom domains alias that endpoint. The URL doesn’t extend the guest’s lease, and a public app still needs its own user authentication.
A dropped connection shouldn’t change the job
Suppose your agent starts a machine and loses the response. Repeating the request with the same Idempotency-Key looks up the original creation. Generating a new key asks for another start. We save the creation receipt before booting, so recovery has something to find.
Once running, an Ad Hoc machine is identified by its slot and exact createdAt timestamp. Slots get reused. A delayed cleanup request must distinguish yesterday’s dashboard from today’s occupant. The account coordinator and runtime enforce those identities; cleanup shouldn’t guess.
Longer commands can use managed executions with retained results and numbered output events. Jobs run for up to fifteen minutes within the machine’s lease, with results retained for an hour. A disconnected viewer can reconnect using its cursor while the job continues within its deadline. A runtime restart is different: unfinished jobs become interrupted, without silently replaying commands. Automatically rerunning a side effect because its reply disappeared is how a “helpful” retry becomes a second invoice.
Put the budget on the server
The Linux guests run on Cloudflare Containers. The account coordinator is a Durable Object, persistent application code outside those guests. It reserves capacity and runtime before provisioning, while a separate controller enforces each machine’s deadlines and access. Concurrent agents share the account’s funding; they can’t each spend the same remaining dollar.
Current prepaid compute starts with a $5 top-up, carries unused funds forward, and has no monthly subscription. Here are representative sizes; provisioning and idle time count too.
| Machine | RAM | Compute / hour |
|---|---|---|
| Lite | 256 MiB | $0.02 |
| Small | 4 GiB | $0.12 |
| XL | 12 GiB | $0.56 |
A separate monthly spending cap bounds consumption. Stopping releases unused runtime reservations; model inference and retained storage have their own usage charges. The cloud bill shouldn’t depend on whether a browser remembered to run its cleanup handler.
Temporary Ad Hoc sessions have idle and hard deadlines. The backend’s newer Production lifecycle renews funded five-minute reservations and supervises a startup command for longer-lived services. Its live rollout still needs qualification. Recovery starts from the image and command, so durable application data belongs outside the guest; persistent disks, replica failover, and an uptime SLA aren’t included.
Buy the service, or run it
The backend and web client are open source under GPLv3, including accounts, billing, and lifecycle enforcement. You can develop locally with Wrangler and a Docker-compatible engine, or adapt a deployment to your own Cloudflare account. That takes operator work, and the infrastructure layer depends on Cloudflare.
With the hosted service, we handle platform deployment and maintenance. A self-hosted deployment leaves those jobs with you, alongside control over the implementation. Start with a small task: build the CSV dashboard, check its totals, download its repository, and run it in your editor. You should leave that experiment with useful software and code you can keep working on.