Skip to content
tentaflake docsv0.4

Isolated AI agents on NixOS

Reproducible infrastructure for Hermes and ZeroClaw, with explicit security boundaries and operational recovery paths.

These docs describe tentaflake v0.4. They are generated from the public repository at a pinned source revision so the website cannot silently drift from the code.

Start with a clean install

Build the installer, provision a host, and reach a verified first boot.

Add an existing NixOS host

Consume tentaflake as a flake input and enable only the modules you need.

Understand the boundary

Review trust assumptions, profiles, brokered egress, and disposable workers before exposing an agent to untrusted work.

Operate and recover

Use the CLI, observability profile, backups, and documented recovery procedures.