PostSteward
Menu

INSTALL POSTSTEWARD

Install the real local runtime.

PostSteward Cloud owns identity, provider OAuth and the executor fence. The installed PostSteward runtime owns local projects, schedules, portfolio work, receipts and Setup & Recovery.

Install

curl -fsSL --proto '=https' --tlsv1.2 https://poststeward.com/install.sh | bash

Read the PostSteward installer at poststeward.com/install.sh

Linux · Bash · Python 3.10 or newer. Installation starts inactive; review pairing and activation in your workspace. WSL and macOS acceptance is still pending. Full installation guide.

The installer is no-root, pins an exact release, verifies the embedded runtime tree and then starts machine pairing when a terminal is available.

Pair and connect

poststeward onboard
poststeward status --json
poststeward doctor --json

Approve the exact machine in the owner workspace, then connect X, Threads and/or LinkedIn there. Provider secrets remain cloud-side; the local runtime receives only an installation token and non-secret verified account bindings.

Configure local Fresh state

poststeward configure \
  --project example-project \
  --label "Example Project" \
  --timezone Europe/London \
  --pace regular \
  --text-file first-reviewed-post.txt

Preview first, then apply the exact returned SHA-256. The initial campaign remains manual-only.

One executor, one effect fence

The owner explicitly hands execution from hosted mode to one paired local installation. Local provider effects require a live lease plus the current authority generation and cross the existing D1 external-effect ledger before X, Threads or LinkedIn is called.

No split brain.

Hosted publishing is fenced while local execution is active. Local deactivation self-fences the cloud generation before closing the local marker/timers; hosted execution is not automatically re-enabled.

Agents

poststeward help --json
poststeward portfolio status --json
poststeward schedule list
poststeward cloud mcp

Humans retain OAuth/admin/recovery authority. Agents consume deterministic local JSON surfaces or scoped remote MCP/HTTP grants.

Lifecycle

poststeward activate --json
poststeward deactivate --reason "maintenance" --json
poststeward update --channel stable --dry-run

Activation, deactivation and executor handoffs remain review/evidence gated. Updating an active local publisher is refused.