24/7 Remote AI Coding on VPS: Herdr, Tailscale, Termius, and Claude CLI Non-Root Tips
A practical workflow for running Herdr and AI coding CLIs 24/7 on a VPS, accessing them securely via Tailscale and Termius, and configuring Claude CLI non-root
Developer Fabricio Adrian (@segueofabricio) shared a practical workflow on X (formerly Twitter) for moving AI coding agents from local laptops to an always-on cloud Virtual Private Server (VPS), combining an encrypted mesh network with mobile SSH tools to build an autonomous 24/7 remote development setup. The configuration removes physical machine dependencies while maintaining secure mobile access on the go.
Running agentic AI coding CLIs like Claude Code or Codex directly on a local desktop or laptop quickly exposes physical hardware constraints. When an active development session runs for hours, closing the laptop lid or entering sleep mode sends a termination signal to terminal processes, interrupting running test suites and builds. Battery drain and volatile public Wi-Fi further complicate running long-horizon autonomous tasks. Adrian argues that keeping an entire agent coding workflow locked to a local PC is outdated, advocating instead for an uninterrupted cloud VPS serving as the central compute brain, while laptops and smartphones function as lightweight, portable clients.
1. An Always-On VPS Foundation and Autonomous Herdr Orchestration
The core premise of this remote architecture is shifting compute burdens entirely off the local machine into a persistent, unmanaged cloud environment.
- VPS as the Always-On Compute Hub: By hosting agent environments on a cloud VPS (Virtual Private Server), tasks remain completely insulated from residential power cuts, domestic internet drops, and laptop overheating. The agent continues executing code uninterrupted whether the developer is sleeping or traveling.
- Deploying Herdr Orchestrator: The workflow deploys Herdr (https://herdr.dev/) on the VPS, using it as an orchestration layer to supervise multiple coding agent CLIs and background tasks in a structured manner.
- Enabling YOLO Mode for Unattended Execution: Instead of running coding agents in interactive mode—where every file write or terminal execution halts to await manual confirmation—Adrian enables autonomous execution, known as YOLO ("You Only Live Once") mode. This allows the agent to self-direct through coding, testing, and error-fixing loops without requiring manual terminal prompts.
2. Hardened Access: Tailscale Mesh VPN and Mobile Termius Control
Relocating developer environments to a cloud server introduces security challenges. Leaving raw SSH access exposed to the open internet is dangerous, requiring a hardened access strategy.
- Tailscale Mesh Networking Without Exposed Ports: Opening port 22 directly on a public server IP invites automated brute-force attacks, and connecting from untrusted airport or coffee shop Wi-Fi risks credential interception. Adrian emphasizes avoiding exposed public IPs by routing all traffic through Tailscale's WireGuard-based private mesh network. Connections between the VPS, phone, and local workstation remain end-to-end encrypted without exposing open firewall ports.
- Mobile Control via Termius: By installing the Termius SSH client on a smartphone and connecting to the VPS over the private Tailscale IP, developers can check agent progress, inspect git diffs, and issue new coding instructions directly from their phones during commutes or away from a desk.
- Local Dev Server Routing: When web apps or API services run inside the VPS, Tailscale allows developers to easily access those remote development ports from a local laptop browser for real-time visual inspection.
3. Critical Privilege Rule: Dedicated Non-Root User for Claude Code CLI
The most critical operational nuance Adrian highlighted from practical experience involves Linux user permissions when configuring the Claude Code CLI.
- Permission Bypass Failures Under Root: A common pitfall when configuring a new Linux VPS is running everything as the
rootsuperuser. However, under Claude Code's security architecture, executing the CLI directly asrootcauses its permission bypass and automated approval mechanisms to fail or misbehave. - Dedicated Non-Root User Setup: To ensure uninterrupted autonomous execution, developers must create a dedicated non-root user account (such as
devoragent) with sudo privileges on the VPS. Installing and launching Claude Code CLI strictly within that standard user environment ensures tool-calling bypass policies function properly.
4. Remote E2E Testing Automation and Practical Adaptation
Verifying remote code quality without manual overhead and adapting to a smartphone-first terminal workflow require practical adjustments.
- Autonomous E2E Testing with Obscura: Instead of pulling code to a local machine to manually verify that features work, Adrian directs the remote agent to execute end-to-end (E2E) testing flows directly on the VPS using Obscura. The agent autonomously simulates browser interactions and validates user journeys, reporting only final status outcomes.
- Adapting to Mobile Terminal Ergonomics: Operating a terminal workflow on a mobile screen can feel unfamiliar and visually constrained on the first day, but developers quickly adapt once routine commands and status checks become second nature.
- Safety Gates for Production: For developers cautious about running unchecked autonomous agents against critical repositories, community feedback suggests maintaining approval gates specifically for production branch merges or deployments, keeping the day-to-day workflow fast while preventing unintended regressions.
Original source
- X (formerly Twitter) @segueofabricio original thread: ainda codando no seu pc? tão 2025 kkkkk - Remote VPS AI Coding Setup
- Herdr Official Website: Herdr.dev
- Tailscale Official Website: Tailscale.com
- Termius Official Website: Termius.com