EnoughFactory / Guide
A place for the work.
Start with an isolated session. Add agents and devices. Let a goal bring the work together.
Requirements
- A supported Mac or Linux device. Release targets are Apple Silicon Mac and Linux x64/ARM64 on glibc distributions.
- Space for the factory’s runtime, container images and project workspaces. Mac uses a private Linux VM; Linux uses a dedicated rootless engine.
- A Git repository and the project’s environment configuration.
- Your own account or API credentials for the agent runtime you use.
EnoughFactory bundles its container tools, Node runtime and envmux executable. Packaged applications do not need development SDKs or your own Docker installation. Linux host prerequisites are listed below.
EnoughFactory does not include provider subscriptions or model usage. Authentication and quotas come from the connected agent account.
Installation
Choose the package that matches your operating system and processor from Downloads. Check its SHA-256 checksum before installation. Packages identify whether they are signed.
On Mac, open the DMG and drag EnoughFactory into Applications, or extract the application ZIP. On Linux, make the AppImage executable and open it, or extract the tar archive and run the application. Keep its resources directory alongside it. If your distribution cannot open an AppImage, use its --appimage-extract option.
Open Settings → EnoughFactory runtime → Prepare runtime to start the private engine. Mac bundles a pinned, verified Linux guest image and prepares its writable VM disk on first start, with progress visible in the app. Its Lima VM uses Apple’s virtualization framework. On Linux, the bundled engine runs under your regular user with a private socket and storage. Initial runtime setup, container base images and provider tools can still need a network connection.
The device service owns runtime startup, recovery and shutdown independently of the window. Closing the app leaves running work intact. Stop active environments explicitly before stopping the runtime. Agents retain full permissions inside their containers; rootless host execution does not remove container root access.
Your existing Docker contexts, daemon, images and volumes remain separate. The source distribution includes device-service installation and removal instructions for each supported operating system.
Linux setup
Run the device service as your regular user. The private rootless engine needs UID/GID mapping helpers, permitted user namespaces and at least 65,536 subordinate IDs for your account in both /etc/subuid and /etc/subgid.
On Debian or Ubuntu, install the host helpers:
sudo apt install uidmap iptables util-linux procpsOn Fedora:
sudo dnf install shadow-utils iptables util-linux procps-ngInspect the existing account and ID allocations:
getent passwd "$(id -u)"
cat /etc/subuid /etc/subgidIf either file lacks a range of at least 65,536 IDs for your account, ask the host administrator to assign a free, non-overlapping range in each file, then restart the private runtime. The app reports missing helpers and mappings.
If the host disables user namespaces, its administrator needs to enable them according to local policy. Ubuntu can also require an AppArmor profile for the actual bundled RootlessKit path shown by the app. Use an application-specific profile and preserve the host’s other protections. Rootless prerequisites and troubleshooting.
Some Ubuntu hosts also require a rule for the desktop app’s Chromium sandbox. Extract the tar package or AppImage into a stable directory, then run its bundled setup helper as the host administrator:
cd /path/to/extracted-app
sudo ./resources/runtime/node ./resources/install/configure-linux-desktop-sandbox.mjs --executable ./enoughfactoryReplace the example path with the installed application’s directory. The helper allows sandbox namespaces for that exact executable. Keep the application at that path, and repeat setup if you move it. The desktop continues to use Chromium’s sandbox.
Build from source
Source builds require Node 22.14 or newer, pnpm 10.34.5 and the .NET 10 SDK. Prepare the pinned container tools for your current operating system and architecture before opening the app:
git clone https://github.com/enoughtools/EnoughFactory.git
cd EnoughFactory
pnpm install --frozen-lockfile
pnpm --filter @enoughfactory/envmux build:engine
node scripts/prepare-container-runtime.mjs
pnpm build
pnpm desktopRuntime preparation downloads pinned OSS archives and verifies their SHA-256 values, including Mac’s guest image. It prepares EnoughFactory’s own assets; it does not install or take over your host’s Docker daemon. The app prepares its private writable VM disk from that verified image on first start.
Use the repository’s version-matched installation instructions for service startup, removal, custom paths and platform diagnostics.
Your first session
- Add a local Git repository as a project.
- Review its environment setup and create a session.
- Follow startup progress, then open services, output, a terminal or an application preview.
- Make changes yourself or work with an agent.
- Inspect the Changes view and stop the session when you are ready to recover its work through Git.
Envmux owns the environment lifecycle. EnoughFactory gives that environment one workspace with clear progress, errors and recoverable results.
Agents and goals
Choose a supported agent and connect its provider account. Conversations, tool activity and artifacts are stored on the device that owns the session. A disconnected device makes that conversation unavailable until it returns.
A goal adds completion criteria, a plan and persistent work records. The factory chooses tasks, places attempts on eligible devices and evaluates their evidence. A completed agent turn does not automatically complete the goal.
When a result needs repair, autonomous mode chooses the next action and continues. When authentication, a budget or a genuine missing input prevents progress, the workspace shows what it needs.
Autonomy and approvals
These are independent settings.
- Manual
- You choose each next task.
- Assisted
- The factory helps plan the work and proposes the next action.
- Autonomous
- The factory chooses, executes and evaluates next actions toward the goal.
- Approve all
- Enough handles supported approval requests automatically, including when the window is closed.
- Rules
- Your configured policy handles matching requests. Unresolved requests appear in the workspace.
- Manual approvals
- Review the request in Enough and return a decision to the waiting runtime.
Agents receive full permissions inside their containers. Runtime adapters report the approval requests they actually support. Some full-access routes emit no approval requests; selective policies do not promise a separate decision for every effect inside an allowed command.
Connect devices
Install the device service on each machine and pair it through the app’s invitation flow. Paired devices authenticate their identities before accepting control.
WebRTC is the preferred connection between devices. Signaling helps them discover and negotiate a connection; an optional TURN relay supports networks where a direct connection fails.
Keep chats on their owning device. An offline machine’s live tools are unavailable, while Enough keeps ownership and last-known state visible. Unknown execution state is reconciled before the factory retries work.
Architecture
The shared React interface runs in Electron or a browser. A device service owns the private container runtime, local sessions, agent connections, approvals and networking. A selected coordinator keeps durable goals, tasks and attempts.
Envmux supplies isolated environments on the owned engine and its explicit socket. Mac VM shares are limited to factory-owned directories. Git supplies ordinary workspaces; ArtifactFS is available only on runtimes verified to support its trusted mount manager. Transactional coordination records and evidence manifests remain separate from the workspace filesystem.
Remote previews use an authenticated HTTP/WebSocket gateway over the device connection. A WebRTC data channel is a transport, rather than a browser URL.
Self-hosting
The device service and signaling service ship with the source. Configure signaling and optional relay services for your network. The signaling service exchanges presence and connection negotiation; it does not store your conversations or own your goals.
Use the version-matched source instructions for setup, service startup, removal and configuration. Keep provider credentials on the appropriate device and configure project integrations deliberately.
Open the source instructionsOpen source
EnoughFactory’s application code is MIT licensed. Upstream licenses and notices accompany the release, including envmux and EnoughUI. Supplied typefaces retain their SIL Open Font License notices.
The bundled container engine has matching source archives, build recipes and relink materials. Mac’s bundled Ubuntu guest has a separate package-source companion with both source parts, archive evidence, lock and instructions. These materials accompany the executable release and keep their upstream licenses.
Download the runtime source companions
Contributions should keep the complete product understandable: coherent interface, replaceable adapters, durable state and meaningful verification. The repository’s contributor guide describes local setup and the checks relevant to a change.
Browse the repository