burrowee

The signed, self-service install channel for the Burrowee platform.

Install

Each installer detects your OS and architecture, verifies the download end-to-end (minisign signature → SHA-256 → unzip), then drops the burrowee dispatcher plus the component. burrowee <comp> … and the bare burrowee-<comp> binary both work.

CLI — connect, ssh, pair, relays
curl -fsSL --proto '=https' --tlsv1.2 https://release.burrowee.com/cli/install.sh | sh Copy
Gateway — expose a host's services
curl -fsSL --proto '=https' --tlsv1.2 https://release.burrowee.com/gateway/install.sh | sh Copy
Edge — self-hosted relay
curl -fsSL --proto '=https' --tlsv1.2 https://release.burrowee.com/edge/install.sh | sudo sh Copy
Agent — AI-agent identity client
curl -fsSL --proto '=https' --tlsv1.2 https://release.burrowee.com/agent/install.sh | sh Copy

Verify by hand

Every release ships SHA256SUMS.txt and a minisign signature. The signing public key lives at /burrowee-release.pub — it is also baked into the installer, which is the trust anchor that verifies each download automatically. To check a download yourself:

minisign -V -P "$(cat burrowee-release.pub | tail -n1)" -m SHA256SUMS.txt -x SHA256SUMS.txt.minisig
f=<file>                                      # the file you downloaded
want=$(awk -v f="$f" '{ n = $2; sub(/^\*/, "", n); if (n == f) { print $1; exit } }' SHA256SUMS.txt)
got=$(shasum -a 256 "$f" | awk '{print $1}')  # sha256sum "$f" on Linux
if   [ -z "$want" ];        then echo "NO ENTRY for $f in SHA256SUMS.txt — do not install"
elif [ "$want" = "$got" ];  then echo "OK $f"
else                             echo "MISMATCH for $f — do not install"; fi
Copy

A failed signature check means the bytes are untrusted — do not install them.

Supported platforms

OSarm64amd64
macOS (darwin)✓✓
Linux✓✓

Windows is not supported.

Documentation

Full user guides — getting started, install, gateway, CLI, and reference:

For coding agents

Skill packages for fresh-context LLM agents — point an agent at any of these: