Appearance
Create an agent in your cloud
The create-agent wizard builds agents on virtual machines in a cloud account you connected to Kadmo. You pick the software, the machine, the roles and the names; when you click Launch, Kadmo creates the server, its SSH key and its firewall in your account, installs the agent, and the new agent appears on Agent Fleet. This page walks through the wizard step by step and explains what happens after you launch.
In this release
The app reaches agents over Kadmo's private network, so a launch is accepted only where the app can reach the new machine:
- AWS: the connection must name an agent subnet that is peered with Kadmo's network, and the agent launches in that subnet's region. Book a call to set up the peering, then see The agent subnet.
- Hetzner: Launch is refused with "Hetzner agents have no private network this app can reach yet — launch on an AWS connection with an agent subnet".
Agents hosted by Kadmo need none of this: see Request a hosted agent.
Before you start
| You need | Why | Where |
|---|---|---|
| The admin role on your account | Creating agents and cloud connections is an admin action | Team |
| A connected cloud account | The wizard launches into it | Connect AWS or Connect Hetzner |
| At least one workspace | Every agent is assigned to a workspace, whose repositories it checks out | Workspaces |
| Room under your agent limit | The Create Agent button is disabled at the limit ("Agent limit reached") and after a trial ends | Agent Fleet header |
Open the wizard
On Agent Fleet, click Create Agent. When no cloud is connected yet, the page shows Connect Cloud instead, which takes you to Integrations.
The wizard opens as a wide panel:
- a step rail on the left with the four steps and a one-line summary of each,
- the current step in the middle,
- a Build sheet on the right that lists what will be built and ends in Est. total, the estimated monthly cost.
Every step opens with working defaults, and you can click any step in the rail at any time. Skip to launch → jumps to the last step. Next checks only the step you are on; Launch checks all four, and when one is incomplete the footer names it and links to it. The wizard remembers your draft in the browser tab until you launch.
Step 1: Software
"Pick the profile and the agent app, then the components baked onto the box."
| Field | What it decides |
|---|---|
| Profile | The software preset. SWE Full Stack (the default: Claude Code, Chrome, the agent runtime, the Chrome extension and skill packs), SWE .NET (adds the .NET 9 SDK) and SWE Android (adds JDK 17, the Android SDK and the Android Emulator). Profiles your team saved appear under Your profiles |
| Agent app | Which coding app and model provider the agent runs. Your account's default app is pre-selected. Providers and API keys are managed on Agent Apps; see Agents |
| Deliver only this app to this agent | Off by default. On, only the picked app's settings are placed on the machine. You can change it later on the agent's page |
| Components | Three groups: Core (browser, dispatch, packs), Toolchains (Docker, PostgreSQL client, .NET 9, Elixir, Android) and Network access (OpenVPN, WireGuard, RDP client) |
A few rules shape the component list:
- Required components are ticked and locked with a Required chip and the reason (for example, skill packs are always installed, and a component another one depends on is added with it).
- A component that needs a config file (a VPN profile, for example) can take the file right in its row, up to the size shown there. Launching without the file is fine: the component installs and stays inactive until the file lands, and the wizard warns you about it.
- Size floors gate Launch. The Android Emulator needs a KVM-capable machine (on AWS the XL size); no Hetzner type offers KVM.
- Changing the components marks the profile Customized. An admin can save the mix as a team profile under Machine → Team defaults.
Step 2: Machine
"Where the agent runs: cloud connection, region and machine size."
| Field | What it decides |
|---|---|
| Cloud connection | Which connected account to launch into. None yet? "Add one in Integrations → Cloud" |
| Region | Where the machine runs. On AWS it must be the connection's default region, where its agent subnet is |
| Machine size | One of four sizes, each card showing vCPUs, memory, the monthly estimate and the instance type |
| Use spot pricing | AWS only: "Up to ~70% cheaper. AWS may reclaim the VM at any time." A reclaimed spot machine stops and restarts when capacity returns. "Spot pricing not available on Hetzner." |
Machine sizes
The estimates are Kadmo's price catalogue (on-demand, per month); your cloud bills the real price.
| Size | AWS | Hetzner |
|---|---|---|
| Small (S) | t3a.medium · 2 vCPU · 4 GB · about $21 (spot about $6) | CX23 · 2 vCPU · 4 GB · about $5 |
| Medium (M), the default | t3a.large · 2 vCPU · 8 GB · about $41 (spot about $12) | CX33 · 4 vCPU · 8 GB · about $9 |
| Large (L) | t3a.xlarge · 4 vCPU · 16 GB · about $82 (spot about $25) | CX43 · 8 vCPU · 16 GB · about $19 |
| XL (LX) | m8i.xlarge · 4 vCPU · 16 GB · KVM · about $140 (spot about $42) | CCX23 · 4 vCPU · 16 GB · dedicated vCPU · about $53 |
Regions
| AWS | Hetzner |
|---|---|
us-east-1 N. Virginia, us-east-2 Ohio, us-west-1 N. California, us-west-2 Oregon, eu-central-1 Frankfurt, eu-west-1 Ireland, eu-west-2 London, eu-north-1 Stockholm, ap-southeast-1 Singapore, ap-southeast-2 Sydney, ap-northeast-1 Tokyo, ap-south-1 Mumbai | fsn1 Falkenstein, nbg1 Nuremberg, hel1 Helsinki, ash Ashburn, VA, hil Hillsboro, OR, sin Singapore |
Your account's admins can narrow the profiles, sizes and regions everyone is offered under Settings → Cloud → Provisioning options.
Availability check
When you pick a size, the wizard asks the provider whether it can launch it there:
- A size the region does not offer, or that is sold out, is greyed out and blocks Launch ("… is not offered in … — pick another machine size or region").
- When the standard sizes are short, Load N more sizes the provider stocks right now reveals more machine types.
- Other findings (a disabled region, a zero vCPU quota, a missing agent subnet) show under the sizes. The fixes are in the AWS and Hetzner troubleshooting tables.
- When the check itself cannot run, nothing is greyed out, and the provider decides at launch.
Team defaults
Admins see a Team defaults panel: Save as account defaults pre-selects this profile, region and machine size for everyone on your account, and Save as team profile saves a customized component mix, with its roles and tools, under Your profiles.
Step 3: Roles & tools
"What the agent is allowed to do, and which tool sets it ships with."
| Field | What it decides |
|---|---|
| Roles | The roles from your account's role registry (built-ins plus the roles your skill pack ships). At least one is required |
| Agent tools | The tool plugins the agent runtime loads. Picking roles pre-selects their tools; once you edit the list by hand, changing roles no longer updates it |
| Claude Code plugins | Optional: plugins from the marketplaces your account allows, entered as Marketplace and Plugin |
Step 4: Name & launch
"Assign workspaces, name the batch, and keep the shared RDP password somewhere safe."
| Field | Rules |
|---|---|
| Workspaces | At least one. The agent checks out their repositories. You can change the assignment after the agent is online |
| Agents | One name per agent, up to 10 per batch. Lowercase letters, digits and dashes, up to 64 characters, unique in the batch and on your account |
| RDP password | Generated for you and shared by every agent in the batch. Copy it now; you need it for a remote-desktop login |
Click Launch (or Launch N agents). The button counts through the batch. If one agent fails, the agents before it keep launching and the wizard keeps the rest, so you can fix the name and click Launch again.
After Launch
Each new agent appears at the top of Agent Fleet as a provisioning card with five steps:
| Step | What happens |
|---|---|
| Validate | Kadmo checks the connection's credentials |
| Security group | It creates or updates your account's shared firewall |
| Launch | It starts the server |
| Install deps | The machine installs the desktop, Chrome, the coding app and the agent runtime |
| Heartbeat | Kadmo waits for the agent's first check-in |
The card shows the elapsed time and each step's message. A new agent usually reports Online in about ten minutes.
When the agent first checks in, its setup is still finishing, so Kadmo holds it for 15 minutes: the card shows Paused · 15m left and takes no automatic work. Your workspace repositories are checked out during the hold, and you get an "agent ready" e-mail. To use it sooner, open the agent and click Resume now.
If no check-in arrives within 15 minutes of launch, the card turns Failed with "Timed out after 15 minutes waiting for the agent's first heartbeat — the VM may have failed to boot or finish installing." Open Details → shows the full log. Delete clears a failed attempt that never got a server; when a server was already created, Delete refuses ("Provisioned VM still exists — open Details and destroy it") and you remove it with Destroy on the agent page. A machine that checks in late still recovers to Online.
While a card is still provisioning, Cancel stops the launch and terminates anything it already created.
The first job
On the Kadmo agent app the agent is ready to work. On a Claude Code (subscription) app, its first job stops at Not logged in until someone signs in once on its live desktop; the Sign in Agent Apps strip on Agent Fleet walks you through it. See Use your Claude subscription.
Related
- Agents: statuses, holds, agent apps and how agents stay current
- Connect AWS and Connect Hetzner
- Orchestration: sending work to your agents