Automate & run unattended
Once sailor run --once works, you can run the agent on a schedule or as a long-lived loop. The scaffold's sail-automation skill offers four options, by reliability and infra overhead:
GitHub Actions (cloud runner, zero infra) — the scaffold's
.github/workflows/agent-tick.ymlrunssailor run --onceon a cron;sailor trigger githubfires it on demand. Simplest, but cron timing drifts.Self-hosted runner — the same workflow on your own machine for reliable timing.
Docker — the
sailmoney/sailorimage on any VM or cloud, via a container registry (see Docker).Local daemon —
sailor service installregisters an OS service (launchd / systemd / Task Scheduler) that restarts on crash;sailor service status/stop/logs/uninstallmanage it. No Docker required.
The rest of this page details option 1 (GitHub Actions), the zero-infra default.
GitHub Actions — one-time setup
1. Export the CI keystore.
sailor keys export-ciThis copies the encrypted agent-wallet keystore to ci-keystore.json in the project root and allowlists it in .gitignore. The geth v3 keystore is safe to commit — the raw private key is never exposed; it can only be unlocked with the passphrase.
2. Commit the files the runner needs.
ci-keystore.json
.sail/account.json
.sail/mandate.json3. Add two repository secrets (Settings → Secrets and variables → Actions):
SAIL_PASSPHRASE
the passphrase that encrypts the agent wallet
RPC_URL
your RPC endpoint for the agent's chain
How the workflow runs
On each scheduled tick the workflow copies ci-keystore.json to .sail/keys/manager.json, then runs npx sailor run --once with SAIL_PASSPHRASE set so the manager key is unlocked non-interactively. No private key ever appears in the workflow file or in the secrets — only the passphrase and RPC URL do, and the keystore is encrypted.
Fire it manually without waiting for the cron:
Safety notes
The agent in CI is still bounded by the on-chain mandate — CI cannot make it exceed its permissions.
You can pause the session at any time (
sailor session pause); a paused session makes every scheduled tick a no-op until you resume.Never commit
SAIL_PASSPHRASEor any raw private key. Only the encryptedci-keystore.jsonis committed.
The sail-automation skill walks through all four options if you're operating via a coding agent.
Last updated

