Skip to content

Create an agent in your cloud ​

The create-agent wizard builds agents on virtual machines in a cloud account you connected to Kadmo. You pick the software, the machine, the roles and the names; when you click Launch, Kadmo creates the server, its SSH key and its firewall in your account, installs the agent, and the new agent appears on Agent Fleet. This page walks through the wizard step by step and explains what happens after you launch.

In this release

The app reaches agents over Kadmo's private network, so a launch is accepted only where the app can reach the new machine:

  • AWS: the connection must name an agent subnet that is peered with Kadmo's network, and the agent launches in that subnet's region. Book a call to set up the peering, then see The agent subnet.
  • Hetzner: Launch is refused with "Hetzner agents have no private network this app can reach yet — launch on an AWS connection with an agent subnet".

Agents hosted by Kadmo need none of this: see Request a hosted agent.

Before you start ​

You needWhyWhere
The admin role on your accountCreating agents and cloud connections is an admin actionTeam
A connected cloud accountThe wizard launches into itConnect AWS or Connect Hetzner
At least one workspaceEvery agent is assigned to a workspace, whose repositories it checks outWorkspaces
Room under your agent limitThe Create Agent button is disabled at the limit ("Agent limit reached") and after a trial endsAgent Fleet header

Open the wizard ​

On Agent Fleet, click Create Agent. When no cloud is connected yet, the page shows Connect Cloud instead, which takes you to Integrations.

The wizard opens as a wide panel:

  • a step rail on the left with the four steps and a one-line summary of each,
  • the current step in the middle,
  • a Build sheet on the right that lists what will be built and ends in Est. total, the estimated monthly cost.

Every step opens with working defaults, and you can click any step in the rail at any time. Skip to launch → jumps to the last step. Next checks only the step you are on; Launch checks all four, and when one is incomplete the footer names it and links to it. The wizard remembers your draft in the browser tab until you launch.

Step 1: Software ​

"Pick the profile and the agent app, then the components baked onto the box."

FieldWhat it decides
ProfileThe software preset. SWE Full Stack (the default: Claude Code, Chrome, the agent runtime, the Chrome extension and skill packs), SWE .NET (adds the .NET 9 SDK) and SWE Android (adds JDK 17, the Android SDK and the Android Emulator). Profiles your team saved appear under Your profiles
Agent appWhich coding app and model provider the agent runs. Your account's default app is pre-selected. Providers and API keys are managed on Agent Apps; see Agents
Deliver only this app to this agentOff by default. On, only the picked app's settings are placed on the machine. You can change it later on the agent's page
ComponentsThree groups: Core (browser, dispatch, packs), Toolchains (Docker, PostgreSQL client, .NET 9, Elixir, Android) and Network access (OpenVPN, WireGuard, RDP client)

A few rules shape the component list:

  • Required components are ticked and locked with a Required chip and the reason (for example, skill packs are always installed, and a component another one depends on is added with it).
  • A component that needs a config file (a VPN profile, for example) can take the file right in its row, up to the size shown there. Launching without the file is fine: the component installs and stays inactive until the file lands, and the wizard warns you about it.
  • Size floors gate Launch. The Android Emulator needs a KVM-capable machine (on AWS the XL size); no Hetzner type offers KVM.
  • Changing the components marks the profile Customized. An admin can save the mix as a team profile under Machine → Team defaults.

Step 2: Machine ​

"Where the agent runs: cloud connection, region and machine size."

FieldWhat it decides
Cloud connectionWhich connected account to launch into. None yet? "Add one in Integrations → Cloud"
RegionWhere the machine runs. On AWS it must be the connection's default region, where its agent subnet is
Machine sizeOne of four sizes, each card showing vCPUs, memory, the monthly estimate and the instance type
Use spot pricingAWS only: "Up to ~70% cheaper. AWS may reclaim the VM at any time." A reclaimed spot machine stops and restarts when capacity returns. "Spot pricing not available on Hetzner."

Machine sizes ​

The estimates are Kadmo's price catalogue (on-demand, per month); your cloud bills the real price.

SizeAWSHetzner
Small (S)t3a.medium · 2 vCPU · 4 GB · about $21 (spot about $6)CX23 · 2 vCPU · 4 GB · about $5
Medium (M), the defaultt3a.large · 2 vCPU · 8 GB · about $41 (spot about $12)CX33 · 4 vCPU · 8 GB · about $9
Large (L)t3a.xlarge · 4 vCPU · 16 GB · about $82 (spot about $25)CX43 · 8 vCPU · 16 GB · about $19
XL (LX)m8i.xlarge · 4 vCPU · 16 GB · KVM · about $140 (spot about $42)CCX23 · 4 vCPU · 16 GB · dedicated vCPU · about $53

Regions ​

AWSHetzner
us-east-1 N. Virginia, us-east-2 Ohio, us-west-1 N. California, us-west-2 Oregon, eu-central-1 Frankfurt, eu-west-1 Ireland, eu-west-2 London, eu-north-1 Stockholm, ap-southeast-1 Singapore, ap-southeast-2 Sydney, ap-northeast-1 Tokyo, ap-south-1 Mumbaifsn1 Falkenstein, nbg1 Nuremberg, hel1 Helsinki, ash Ashburn, VA, hil Hillsboro, OR, sin Singapore

Your account's admins can narrow the profiles, sizes and regions everyone is offered under Settings → Cloud → Provisioning options.

Availability check ​

When you pick a size, the wizard asks the provider whether it can launch it there:

  • A size the region does not offer, or that is sold out, is greyed out and blocks Launch ("… is not offered in … — pick another machine size or region").
  • When the standard sizes are short, Load N more sizes the provider stocks right now reveals more machine types.
  • Other findings (a disabled region, a zero vCPU quota, a missing agent subnet) show under the sizes. The fixes are in the AWS and Hetzner troubleshooting tables.
  • When the check itself cannot run, nothing is greyed out, and the provider decides at launch.

Team defaults ​

Admins see a Team defaults panel: Save as account defaults pre-selects this profile, region and machine size for everyone on your account, and Save as team profile saves a customized component mix, with its roles and tools, under Your profiles.

Step 3: Roles & tools ​

"What the agent is allowed to do, and which tool sets it ships with."

FieldWhat it decides
RolesThe roles from your account's role registry (built-ins plus the roles your skill pack ships). At least one is required
Agent toolsThe tool plugins the agent runtime loads. Picking roles pre-selects their tools; once you edit the list by hand, changing roles no longer updates it
Claude Code pluginsOptional: plugins from the marketplaces your account allows, entered as Marketplace and Plugin

Step 4: Name & launch ​

"Assign workspaces, name the batch, and keep the shared RDP password somewhere safe."

FieldRules
WorkspacesAt least one. The agent checks out their repositories. You can change the assignment after the agent is online
AgentsOne name per agent, up to 10 per batch. Lowercase letters, digits and dashes, up to 64 characters, unique in the batch and on your account
RDP passwordGenerated for you and shared by every agent in the batch. Copy it now; you need it for a remote-desktop login

Click Launch (or Launch N agents). The button counts through the batch. If one agent fails, the agents before it keep launching and the wizard keeps the rest, so you can fix the name and click Launch again.

After Launch ​

Each new agent appears at the top of Agent Fleet as a provisioning card with five steps:

StepWhat happens
ValidateKadmo checks the connection's credentials
Security groupIt creates or updates your account's shared firewall
LaunchIt starts the server
Install depsThe machine installs the desktop, Chrome, the coding app and the agent runtime
HeartbeatKadmo waits for the agent's first check-in

The card shows the elapsed time and each step's message. A new agent usually reports Online in about ten minutes.

When the agent first checks in, its setup is still finishing, so Kadmo holds it for 15 minutes: the card shows Paused · 15m left and takes no automatic work. Your workspace repositories are checked out during the hold, and you get an "agent ready" e-mail. To use it sooner, open the agent and click Resume now.

If no check-in arrives within 15 minutes of launch, the card turns Failed with "Timed out after 15 minutes waiting for the agent's first heartbeat — the VM may have failed to boot or finish installing." Open Details → shows the full log. Delete clears a failed attempt that never got a server; when a server was already created, Delete refuses ("Provisioned VM still exists — open Details and destroy it") and you remove it with Destroy on the agent page. A machine that checks in late still recovers to Online.

While a card is still provisioning, Cancel stops the launch and terminates anything it already created.

The first job ​

On the Kadmo agent app the agent is ready to work. On a Claude Code (subscription) app, its first job stops at Not logged in until someone signs in once on its live desktop; the Sign in Agent Apps strip on Agent Fleet walks you through it. See Use your Claude subscription.