---
title: "Actana Setup"
url: "https://control.actana.ai/docs/install/actana-setup"
description: "The activation step: mTLS identity, the auto-start unit, --public-host, and the harness prompts."
updated: 2026-09-01T09:02:59+00:00
---

`actana setup` is the command that turns a placed bundle into a running Core. `install.sh` (and `actana place`) stop before this. Setup prints no pairing credential — enroll a client later with `actana pair new`.

## What it does

- Generates the mTLS material and persists it to `~/.config/actana/material.json`.
- Writes the auto-start service: systemd user unit `~/.config/systemd/user/actana-core.service` on Linux, or LaunchAgent `~/Library/LaunchAgents/com.actana.core.plist` on macOS.
- On Linux, offers to enable lingering so the daemon survives logout.
- Offers to install any harness CLI (Claude Code, Codex, Cursor CLI, OpenCode) that is not already on the machine, using each vendor's own installer.
- Registers and starts the service, then waits for the port to answer.
- Registers this Core with **this machine's own** `actana`, so `actana core ls` lists it and it is what `actana session start` means here by default.

Re-running setup is safe: it upgrades in place, keeps this Core's identity, and leaves exactly one unit. Paired clients stay paired. It re-signs the server certificate only when `--public-host` changed.

## `--public-host` and `--port`

`--public-host` is the address the Panel dials. It goes into the server certificate's SAN and into the pairing endpoint. It defaults to the machine's first routable IPv4 — set it explicitly if the machine is behind NAT or reached by DNS name.

`--port` is the port the daemon listens on (default `8443`). `--host` is the bind address (default `0.0.0.0`). `--label` is the alias shown in the Panel (default: the hostname).

## Harness flags and `--yes`

| Flag | Meaning |
| --- | --- |
| `--with-<harness>` | Install this harness CLI without asking. Repeatable. Ids or commands: `--with-claude-code`, `--with-claude`, `--with-codex`, `--with-cursor-cli`, `--with-opencode`. |
| `--no-harnesses` | Do not install or offer any harness CLI. |
| `--yes` | Take the recommended answer to every prompt, including installing every missing harness CLI. |

On a terminal, setup offers each missing harness in turn. With **no terminal** (piped one-liner, cloud-init) it never prompts and installs nothing unless you pass `--with-<harness>`, `--yes`, or `--no-harnesses`. Declining is not permanent:

```bash
actana harnesses install opencode
```

A vendor installer that fails is reported with the vendor's docs URL and never fails your Core install.

## Two doors

If you already have the CLI, `actana install` does both halves in one go — fetch, verify against `SHA256SUMS`, place, then the same activation as setup:

```bash
npm i -g @actana/cli
actana install --public-host core1.example.com --yes
```

`install.sh` stays the door for a machine with no Node: the tarball carries its own pinned runtime. Both fetch the same way. After `install.sh`, run setup as a second command — there is no flag that fuses them.

## See also

- [Install in one command](/docs/install/install-core)
- [Linux and macOS](/docs/install/install-core)
- [Operating a Core](/docs/core/operating)
- [Mint a pairing code](/docs/pairing/create-a-pairing-code)
