| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
AI-Native SecOps Platform
Flocks is an AI-driven SecOps platform built with Python, featuring multi-agent collaboration, HTTP API server, and modern terminal user interface designed to help you with your SecOps tasks.
Flocks supports two deployment methods — choose one:
| Method | Description |
|---|---|
| 3.1 PC Installation | Recommended for local development and production deployment |
| 3.2 Docker Installation | Out-of-the-box, but agent-browser headed mode is currently unavailable |
By default, the project install scripts will try to ensure the requirements above are available automatically when possible.
If automatic npm installation fails during setup, please install npm manually and use version 22.+ or newer.
The following installation options are supported. Choose one to complete the installation, then proceed to 3.1.3 Start service.
Option A: Install with one command (recommended)
Note
Users in mainland China: Please follow the installation instructions in the 简体中文, which provides a mirror-accelerated installation method specifically optimized for users in China.
macOS / Linux
curl -fsSL https://raw.githubusercontent.com/AgentFlocks/flocks/main/install.sh | bashCreates ./flocks under the current directory
Windows PowerShell (Administrator)
powershell -c "irm https://raw.githubusercontent.com/AgentFlocks/flocks/main/install.ps1 | iex"Option B: Install from source code
If you prefer to inspect the repository before installation, clone it locally and run the installer from the workspace:
git clone https://github.com/AgentFlocks/Flocks.git flocks
cd flocksmacOS / Linux
sh ./scripts/install.shWindows PowerShell (Administrator)
powershell -ep Bypass -File .\scripts\install.ps1Option C: Windows installer (EXE, BETA)
Flocks provides an Inno Setup wizard (.exe) for Windows x64. Download the installer for your version from the GitHub Releases page.
| Platform | Download |
|---|---|
| Windows (x64) | FlocksSetup-<tag>.exe |
After installation, use the Start menu or optional desktop shortcut, or open a new terminal and run flocks start so updated PATH and related environment variables take effect. For more details, see packaging/README.md.
Use the flocks CLI to manage the backend and WebUI together in daemon mode. The start command builds the WebUI before launch by default; use flocks restart when you want an explicit full restart.
flocks start
flocks status
flocks logs
flocks restart
flocks stopThe default service address is:
Flocks CLI usage: flocks --help
Note
In the Docker installation, the agent-browser headed mode is currently unavailable.
docker pull ghcr.io/agentflocks/flocks:latestRun the container and mount the host user's ~/.flocks directory into the container:
macOS / Linux
docker run -d \
--name flocks \
-p 5173:5173 \
--shm-size 4gb \
-v "${HOME}/.flocks:/home/flocks/.flocks" \
ghcr.io/agentflocks/flocks:latestWindows PowerShell
docker run -d `
--name flocks `
-p 5173:5173 `
--shm-size 4gb `
-v "${env:USERPROFILE}\.flocks:/home/flocks/.flocks" `
ghcr.io/agentflocks/flocks:latestEXPOSE in the image only documents container ports. You still need -p 5173:5173 to access the service from the host browser.
On machines in mainland China, you can configure uv to use a local PyPI mirror for faster package downloads.
Create ~/.config/uv/uv.toml with:
[[index]]
url = "https://pypi.tuna.tsinghua.edu.cn/simple"
[[index]]
url = "https://pypi.org/simple"
default = trueDocker registry mirror in China
Permission issues for /home/flocks/.flocks after startup:
-v "$HOME/.flocks:/home/flocks/.flocks:Z" \OR
docker run --rm --entrypoint id ghcr.io/agentflocks/flocks
# example result: uid=1001(flocks) gid=1001(flocks) 组=1001(flocks)
sudo chown -R <uid>:<gid> ~/.flocks
# example: sudo chown -R 1001:1001 ~/.flocksflocks start --host 0.0.0.0If remote access from a virtual machine fails, please specify the host as the virtual machine's IP.
The WebUI and API share the same service address and port. API requests use the same-origin /api path, keeping browser cookies and SSE on a single origin for LAN access and reverse-proxy deployments.
Only enable direct browser-to-backend URLs when you explicitly need them:
FLOCKS_WEBUI_DIRECT_BACKEND_URLS=1 \
flocks start --server-host 0.0.0.0 --webui-host 0.0.0.0Since the local-account update, every HTTP path is protected by default — only the WebUI bootstrap pages (/, /auth/*), static assets, and IM platform webhooks (/api/channel/{channel_id}/webhook) are public.
Initial setup:
Non-browser clients (TUI, SDKs, scripts):
All non-browser clients, including local loopback clients, must present an API token. The token lives in ~/.flocks/config/.secret.json under the secret id server_api_token.
On the server, generate (or rotate) the token — it is persisted on the server's local secret store:
flocks admin generate-api-token # prints token; stores under server_api_tokenOn each remote client, store the same token value into the client's own secret file (so the client SDK / TUI can attach it automatically):
flocks admin set-api-token --token <token-from-server>Or attach it directly per request via either header:
Authorization: Bearer <token>
X-Flocks-API-Token: <token>
Smoke test:
curl -H "Authorization: Bearer <token>" https://flocks.example.com/api/healthQuery the live runtime status of a specific session:
curl -H "Authorization: Bearer <token>" \
https://flocks.example.com/api/session/<sessionID>/statusstatus.type is one of idle, queued, busy, retry, compacting, or dreaming. Automation clients can use isProcessing to determine whether accepted work is still running or waiting. idle only means that the session is currently inactive; it does not indicate whether the previous run succeeded.
Reverse-proxy deployments:
Recovery / lost password:
Orphan sessions (CLI / background / inbound channels):
Sessions created without an auth context (CLI commands, background tasks, inbound IM-channel dispatchers) leave owner_user_id empty. The bootstrap admin still sees them, but a later-added member account would not. Backfill ownership with:
flocks admin reassign-orphan-sessions --username admin --dry-run # preview
flocks admin reassign-orphan-sessions --username admin # applyThe command summarises scanned / orphaned / reassigned / failed counts; a non-zero failed exits with code 2 so CI / scripts can detect partial-write situations and re-run after fixing the underlying cause (typically a transient storage error).
Scan the QR code with WeChat to join our official discussion group.
See CONTRIBUTING.md for development setup, coding standards, testing expectations, and Pull Request guidelines.
Apache License 2.0
| Back | FazBrowse Home | New Git URL |