Deploying Trinity
Trinity is open source under the Apache 2.0 license and runs on infrastructure you control: a cloud server, your own hardware, or your laptop. Your agents, credentials and data stay there.
Choose where to run it
DigitalOcean 1-Click
Create a Droplet from the Marketplace image. HTTPS in about ninety seconds, no terminal.
1-Click deployDigitalOcean installer
One command from your terminal, with the admin password and Claude token set before the Droplet exists.
Installer scriptAny Linux server
Hetzner, AWS, GCP, your own hardware. Prebuilt images, serving in about two minutes.
Server installYour own computer
Docker Desktop on macOS, Linux or Windows. Good for trying Trinity and for development.
Local installTrinity 0.9.5 is on the DigitalOcean Marketplace
The 1-Click image has Docker, Caddy, a host firewall and the Trinity release baked in, so first boot pulls nothing. Pick a size from the sizing table before you create it.
40 Agents, One Instance — a DigitalOcean install from zero, live
Sep 2026
I Built a DevOps Agent That Deploys Other Agents
Apr 2026
Control My DGX Spark From Anywhere
Jan 2026
What you need
- •A machine with 8 GB of RAM for a working fleet (4 GB runs the platform and one or two agents). Prebuilt images and the DigitalOcean paths are x86-64; on an ARM server, build from source.
- •Docker with the Compose v2 plugin (
docker compose, no hyphen), and Git. The DigitalOcean paths install both for you. - •A Claude credential for your agents: a subscription token from
claude setup-token(Pro or Max) or an Anthropic API key. Connecting one is the one required step of Trinity's first-run setup; the DigitalOcean installer does it for you. - •Claude Code, to connect to your instance and deploy agents onto it.
DigitalOcean
Marketplace 1-Click (no terminal)
Trinity 0.9.5 is published on the DigitalOcean Marketplace. Create a Droplet from the Trinity image (8 GB recommended, 4 GB minimum). First boot obtains a Let's Encrypt certificate for the Droplet's IP and starts Trinity from images baked into the snapshot, so it is serving over HTTPS about ninety seconds later. No admin account exists yet: open https://<droplet-ip> and the first visitor creates it with an email and password.
Claim it right after creating the Droplet: until then, anyone who finds the IP can. To skip that window, supply the password as cloud-init user-data when you create the Droplet, or use the terminal installer below.
From your terminal
With DigitalOcean's doctl signed in, one command asks for an admin password and a Claude subscription token, creates a 4 vCPU / 8 GB Droplet (about $48/month), installs Trinity, and prints an HTTPS address when it answers. Because the password is chosen up front, the admin account exists from the first boot and there is no claim window.
$ bash <(curl -fsSL https://raw.githubusercontent.com/abilityai/trinity/v0.9.5/scripts/deploy/trinity-do-create.sh)Either way, the first-run setup opens with a Secure this instance step: point a domain at the Droplet and save it as the Public URL, and Trinity obtains a certificate for it on the first visit. A Cloudflare Tunnel can then take the server off the public internet (Public Access).
Any Linux server
On a server, pull-only is the path you want: every platform image and the agent base image are published to GHCR on each release, so nothing is compiled on the box.
git clone https://github.com/abilityai/trinity.git && cd trinity
cp .env.example .env # set ADMIN_PASSWORD (12+ chars)
echo 'TRINITY_IMAGE_TAG=v0.9.0' >> .env # pin a release
./scripts/deploy/start.sh --hosted --unattendedPin a release rather than latest, which moves on every release. The checkout must stay beside the compose file (it mounts ./config/*), and upgrades are a re-run of start.sh --hosted with a new TRINITY_IMAGE_TAG, not a bare docker compose pull. Put TLS in front before exposing it: a reverse proxy with a certificate, or a Cloudflare Tunnel. Plain HTTP on a public IP sends passwords in the clear.
Full details, TLS and tunnel choices, building from source, and every .env key: Single-Server Deployment. Want a walkthrough for creating the VM on Hetzner, AWS or GCP? The Ops Agent's /provision skill guides you through it.
Or let Claude Code do the install: /trinity:deploy-new-instance from the trinity plugin installs Trinity on any server you can SSH into (or in local Docker) and sets up an Ops Agent to manage it.
Your own computer
With Docker Desktop running:
git clone https://github.com/abilityai/trinity.git
cd trinity
./scripts/deploy/start.sh --unattended--unattended generates the admin password and prints it at the end; without it, start.sh asks you to set ADMIN_PASSWORD in .env first. It also generates every other secret (SECRET_KEY, CREDENTIAL_ENCRYPTION_KEY, AGENT_AUTH_SECRET, the Redis passwords) and writes them to .env. Never change CREDENTIAL_ENCRYPTION_KEY or AGENT_AUTH_SECRET afterwards: stored credentials become unreadable and running agents lose their tokens.
The first run builds the agent base image, which takes 5–10 minutes. When the backend reports healthy, open http://localhost and sign in as admin. If port 80 is taken, set FRONTEND_PORT=8090 (or any free port) in .env.
Details: Local Development. An AI coding agent can also drive the whole install from the runbook at docs/AGENT_INSTALL_GUIDE.md.
Connect Claude Code and deploy an agent
Once Trinity is running, from any agent directory in Claude Code:
# Once per machine: your instance URL, then an emailed sign-in code
/trinity:connect
# Per agent: deploy this directory to the instance
/trinity:onboard/trinity:connect creates an MCP API key for you and writes .mcp.json pointing at <your instance URL>/mcp. The sign-in code only goes to addresses on the instance's whitelist (Settings → Access → Email Whitelist); if none arrives, add your email there. MCP keys are listed under Settings → MCP Keys. See Building Agents.
All install paths
| Path | How | Best for | Guide |
|---|---|---|---|
| DigitalOcean Marketplace 1-Click | Create a Droplet from the Trinity image | The quickest route to a server, and the only one with no terminal at any point: HTTPS at the Droplet's IP in about ninety seconds, and you claim the admin account in the browser | Single Server → 1-Click |
| DigitalOcean, from your terminal | trinity-do-create.sh (needs doctl) | The same Droplet with no browser-claim window: you choose the admin password and paste a Claude subscription token before the Droplet exists | Deploy on DigitalOcean |
| Server, prebuilt images | ./scripts/deploy/start.sh --hosted | Any x86-64 Linux VM, serving in about two minutes with no on-box builds | Single Server → Prebuilt images |
| Server, build from source | docker compose -f docker-compose.prod.yml up -d | ARM servers, custom patches, the enterprise overlay | Single Server → Build from source |
| Local, build from source | ./scripts/deploy/start.sh | Your own machine, trying Trinity, development with hot reload | Local Development |
All five share one installer (scripts/deploy/start.sh), one .env contract, and one set of day-two procedures.
Key URLs
| Service | Local | Server |
|---|---|---|
| Web UI | http://localhost | https://trinity.your-domain.com |
| MCP server | http://localhost:8080/mcp | https://trinity.your-domain.com/mcp — the web server proxies /mcp, so an install that exposes only 80/443 still serves MCP |
| Backend API docs | http://localhost:8000/docs | http://your-server:8000/docs, where port 8000 is reachable (the DigitalOcean paths close it to the internet) |
Running it day to day
# Stop (keeps agent containers; picks the right compose file)
./scripts/deploy/stop.sh
# Start (add --hosted on a prebuilt-image install)
./scripts/deploy/start.sh
# Health check after any change
./scripts/deploy/verify-platform.shNever stop Trinity with docker compose down. It removes the agent network, and every agent then loops trying to restart against a network that no longer exists. If it already happened, run docker compose up -d, docker rm -f the stale agent containers, and start them again from the UI. Their workspaces are kept.
- •Upgrading: on a prebuilt-image install, set the new
TRINITY_IMAGE_TAG, check out the matching tag, and re-runstart.sh --hosted. On a source install, pull and rebuild the platform images. Upgrading has the full procedure with rollback. - •Backups: Trinity backs up its database nightly at 03:30 UTC, plus a copy at boot before any migration, on the same disk. Copy them off the machine for disaster recovery. See Backup and Restore.
- •Monitoring: health probes, resource thresholds and recovery patterns are in Monitoring.
- •Ops Agent: trinity-ops-public is a Claude Code agent that runs these operations for you, locally or over SSH. See Ops Agent.
Detailed deployment guides
| DigitalOcean | One command from your terminal to an HTTPS Droplet: doctl, a Claude subscription token, an optional domain |
| Single Server | Linux VPS: prebuilt images (--hosted) or build from source, the DigitalOcean 1-Click, every .env key and which compose file forwards it |
| Local Development | Docker Desktop, dev compose, hot reload, what start.sh generates |
| Public Access | Cloudflare Tunnel, TLS postures, webhook surface, Slack/Telegram/WhatsApp integrations, /mcp through the tunnel |
| Hardening a Marketplace Install | Bare IP → domain → tunnel or private network, and how to verify each stage |
| Upgrading | Pre-flight → backup → rebuild or re-pull → restart → verify → rollback |
| Backup and Restore | Automatic nightly backups, manual copies, restore procedure, PostgreSQL |
| Monitoring | Six-probe health check, resource thresholds, recovery patterns |
| Ops Agent | A Claude Code agent for day-to-day operations: health, logs, restarts, updates, rollbacks, and provisioning guides for other clouds |