App Mesh = systemd + cron + remote execution + API.
A lightweight, secure platform that runs, schedules, and remote-controls applications across machines — one C++ daemon with JWT/RBAC security, a CLI, REST APIs, SDKs in 6 languages, and a built-in workflow engine.
Use App Mesh to:
- Operate services — manage long-running processes like systemd does, plus health checks, cgroup limits, Docker apps, multi-tenancy, and a Web GUI.
- Execute remotely — run commands, scripts, or in-memory tasks on any node via CLI, REST, or SDK.
- Power AI agents — provide sandboxed build-and-run environments for AI coding assistants, MCP servers, and LLM agent runtimes.
Start the daemon in Docker:
docker run -d -p 6060:6060 --restart=always --name=appmesh --net=host -v /var/run/docker.sock:/var/run/docker.sock laoshanxi/appmesh:latestManage applications with the appm CLI:
# List registered applications
$ appm ls
ID NAME OWNER STATUS HEALTH PID USER MEMORY %CPU RETURN AGE DURATION STARTS COMMAND
1 pyexec mesh disabled - - - - - - 37s - 0 "python3 ../../bin/py_exec.py"
2 ping mesh enabled OK 747 root 5.9 MiB 0 - 37s 37s 1 "ping cloudflare.com"
3 pytask mesh enabled OK 748 root 29.7 MiB 0 - 37s 37s 1 "python3 ../../bin/py_task.py"
# Register a new application
$ appm add -a myapp -c "ping www.baidu.com"
# View its live output
$ appm ls -a myapp -o
PING www.baidu.com (183.2.172.17) 56(84) bytes of data.
64 bytes from 183.2.172.17 (183.2.172.17): icmp_seq=1 ttl=52 time=34.9 ms
# appm -h for more usageSend tasks to a running application and get responses back through the SDK:
from appmesh import AppMeshClient
client = AppMeshClient()
client.login("USER-NAME", "USER-PWD")
result_from_server = "0"
for i in range(10):
task_data = f"print({result_from_server} + {i}, end='')"
result_from_server = client.run_task(app_name="pytask", data=task_data)
print(result_from_server)For native packages (.deb/.rpm), systemd setup, and cluster initialization, see the Installation Guide and the Dockerfile.
| Capability | What you get |
|---|---|
| Application management | Full remote CRUD and control — cgroup limits, OS user, environment variables, Docker apps, stdin/stdout — with monitoring of start counts, exit codes, errors, and health checks |
| Scheduling | Long- and short-running apps, periodic jobs, cron expressions, custom timings, and policy-driven start/exit behaviors |
| Remote execution | Run commands and scripts on any node; send in-memory tasks to running applications for high-performance computing |
| Workflow engine | GitHub-Actions-style YAML pipelines with DAG scheduling, running natively on App Mesh |
| Security | JWT + RBAC with multi-tenant isolation; OAuth, 2FA; YAML-based user storage (local, or Consul for clustering); SSL/TLS on TCP/HTTP/WebSocket; CSRF tokens; HMAC-PSK verification |
| Observability | Built-in Prometheus exporter, Grafana datasource, Loki integration, host/app resource metrics |
| Clustering | Consul-based cluster management and request forwarding across nodes |
| Extras | File upload/download API, remote shell execution, hot config reload, bash completion |
Runs on Linux, macOS, and Windows (x86 and ARM).
App Mesh's secure remote-execution core makes it a natural runtime for AI workloads:
- Remote sandbox for AI coding assistants — give agents an isolated build-and-run environment instead of your local shell.
- MCP server — manage App Mesh from AI clients over Model Context Protocol (Streamable HTTP with OAuth 2.1, RBAC enforced by the daemon).
- LLM agent runtime — host Claude-Agent-SDK-based agents as managed App Mesh applications; see the architecture design.
- Claude Code plugin and MQTT bridge for IoT scenarios.
Define CI/CD pipelines as YAML — similar to GitHub Actions, but running natively on App Mesh with the built-in Workflow Engine:
- DAG scheduling — jobs run in dependency order, independent jobs in parallel
- 4 step types — shell commands, existing Apps, Task API messages, sub-workflows
- Error handling — retry with exponential backoff,
continue-on-error,finallycleanup blocks - Expressions —
${{ inputs.env }},${{ steps.build.stdout }},success(),failure(),always() - Remote execution — target specific nodes by label or hostname
appm workflow add -f pipeline.yaml # register
appm workflow run pipeline -e env=prod -f # run and follow output
appm workflow runs pipeline # view history| Interface | Details |
|---|---|
| CLI | appm command reference |
| REST | REST APIs · OpenAPI spec |
| Web GUI | app-mesh-ui |
| SDKs | Python · Golang · Rust · Java · JavaScript · C++ |
AI & automation
- Remote build-and-run sandbox for AI coding assistants
- LLM agent runtime hosted as an App Mesh app · architecture and workflow design
- Manage App Mesh from AI clients via MCP (HTTP + OAuth)
Remote computing
- In-memory remote task execution
- Remote command and Python script execution
- Parallel task execution with the Python SDK
Operations & observability
- Observability stack with Grafana, Prometheus, and Loki
- Customize application startup and exit behavior
- Promote a native application into a managed microservice
- Secure REST-based file server
Platform & Kubernetes
- Run non-container applications on Kubernetes
- Kubernetes local-PV provisioning via Open Service Broker
- Secure multi-node cluster with Consul
- Standalone JWT authentication server · JWT auth service with REST API and web UI
| Feature | App Mesh | Supervisor | crontab |
|---|---|---|---|
| Schedule accuracy | Seconds | Seconds | Minutes |
| Language | C++17 | Python | C |
| Web GUI | √ | √ | |
| Command lines | √ | √ | √ |
| SDK | √ | ||
| Cron schedule expression | √ | √ | |
| Manage docker app | √ | ||
| Session login | √ | ||
| Manage stdout/stderr | √ | √ | |
| Health check | √ | ||
| Authentication | √ | √ | |
| Multi-tenant | √ | √ |
- Read the Docs — full documentation
- Installation Guide
- Security
- Workflow Guide
🔗 Library dependencies
Questions and discussions are welcome on Gitter. Licensed under the MIT License.
