* feat(cli): add --foreground flag for systemd and process manager deployments
Adds --foreground / --no-daemon to `openchamber serve` which runs the
server inline in the CLI process instead of spawning a detached daemon child.
Required for systemd Type=simple (and other process managers) that track the
direct child — the always-daemon behavior introduced in #640 broke this use case.
Also documents OPENCHAMBER_HOST (bind address) in --help, which was
implemented but never exposed to users.
* docs: add systemd service guide for VPN/LAN deployments
Documents how to run OpenCode and OpenChamber as separate systemd
user services for persistent access over Tailscale or LAN, using
the new --foreground flag and OPENCODE_HOST to wire them together.
* fix(cli): address foreground mode parity issues from PR review
- Fix Ctrl+C handling: CLI SIGINT handler now defers to server in
foreground mode; dedicated signal handlers perform graceful shutdown
and clean exit
- Restore lifecycle parity: foreground instances write PID/instance
files so status, stop, and restart can discover them
- Add deterministic --foreground --json output: emits stable startup
JSON with port, pid, url, and foreground flag before blocking
* fix(cli): tighten inline foreground behavior for restart UX and JSON-only output
* fix(cli): pass --host to foreground server, reject --json, add --quiet output
- Pass options.host through to startWebUiServer() in foreground mode so
the bind address is respected (fixes localhost-only regression from #750)
- Reject --foreground --json with a clear usage error; --json is only
supported in background (daemon) mode
- Emit resolved port on stdout in --quiet foreground mode, matching
daemon parity
- Update systemd docs to include --host 0.0.0.0 for LAN/VPN access
now that the default bind is 127.0.0.1
* fix(cli): remove duplicate OPENCHAMBER_HOST entry from help text
* fix(cli): emit restart summary before foreground serve() blocks
restart --json (and --quiet / human) with a foreground instance would
hang forever without output because serve() blocks and the post-loop
summary was unreachable. Emit the final output after stop succeeds
but before the blocking serve call — foreground is always sorted last
so all daemon results are already collected.
* fix(cli): restart stops foreground instances without re-attaching
Foreground instances are managed by a process manager (systemd, Docker,
etc.) that will restart them automatically. The restart command now
just stops the foreground instance, records the result, and exits —
no serve() call, no blocking. This makes restart --json and all
other output modes work correctly for foreground instances.
Security note: binding to 0.0.0.0 exposes the server on all network interfaces — use only on trusted networks and protect with firewall rules or --ui-password.
Managed-local path note: OPENCHAMBER_TUNNEL_CONFIG must use a container path under /home/openchamber/.... If the config file references credentials-file, ensure that JSON path is also mounted and reachable inside the container.
Data directory: mount data/ for persistent storage. Ensure permissions:
openchamber # Runs in background by default
openchamber stop # Stop background server
systemd service (VPN / LAN access)
Use --foreground to keep the CLI process alive so systemd (or any other process manager) can track and restart it. Combine with OPENCODE_HOST to connect to an OpenCode instance running as a separate service.
Why set PATH and SSH_AUTH_SOCK?
systemd user services start with a minimal environment — no shell profile is sourced.
Without an explicit PATH, OpenCode won't find tools installed via Homebrew, npm, or ~/.local/bin.
Without SSH_AUTH_SOCK, git operations over SSH (push, pull, clone) will fail.
%t expands to $XDG_RUNTIME_DIR (e.g. /run/user/1000), where most SSH agents write their socket.
--host 0.0.0.0 is required to listen on all interfaces (the default is 127.0.0.1). Use --host <ip> or OPENCHAMBER_HOST=<ip> to bind to a specific interface instead.
What makes the web version special
Remote access - Cloudflare tunnel with QR onboarding. Scan from your phone, start coding.