Self-hosted workers
Your staging site sits behind a VPN, so a hosted browser cannot reach it. A self-hosted worker runs on a machine inside your network and drives the browser from there. It connects out to Stunt Double, so you open no inbound ports.
For a full walkthrough, read Test a product behind your firewall.
What it does
- Reach internal products. Actors assigned to a worker browse from your network, so they can open staging, intranet and local dev servers.
- Outbound only. The worker connects to Stunt Double. Nothing connects in.
- Domain controls. Each worker can be limited to the domains actors need.
- Mixed fleets. Actors without a worker keep using Stunt Double's cloud browser, so one workspace can use both.
Before you start
- Plan. Self-hosted workers are on the Enterprise plan only. On other plans, Settings, then Workers, shows Enterprise feature.
- Role. Only workspace owners and admins can set workers up.
- A host. A machine inside your network with Docker that can reach both
the product you want to test and
app.stuntdouble.io.
Set it up
-
In app.stuntdouble.io, open Settings, then Workers. The page is marked Experimental.
-
Turn on Enable for this workspace.
-
Click Add worker, enter a Name (and a description if you like), then click Create worker.
-
Copy the Docker command shown under Recommended: Docker. The API key in it is shown once, so copy it before you dismiss the panel.
-
Run the command on your host. It looks like this, with your own key:
# Run the worker (auto-restarts on failure; auto-updates via watchtower) docker run -d --name sd-worker --restart unless-stopped \ --label com.centurylinklabs.watchtower.enable=true \ -e SD_WORKER_API_KEY=<your-api-key> \ ghcr.io/stunt-double/worker:latest # Enable auto-updates (one-time per machine; safe to re-run) docker rm -f sd-watchtower 2>/dev/null; docker pull ghcr.io/nicholas-fedor/watchtower:1.19.0 && docker run -d --name sd-watchtower --restart unless-stopped \ -v /var/run/docker.sock:/var/run/docker.sock \ ghcr.io/nicholas-fedor/watchtower:1.19.0 --label-enable --cleanup --interval 300The second command installs Watchtower, which pulls and restarts the worker when a new
:latestships. Skip it if you would rather update by hand. -
Back on Workers, the worker's status changes to Connected once it checks in. Enter an internal URL and click Test connection. The test runs in the worker's browser, so a pass means actors can reach that URL.
-
Assign actors to it. Open an actor, find Self-hosted worker and choose it under Worker. Pick Any self-hosted worker to use whichever one is online when a run starts.
For docker compose or other container setups, expand API key only to copy
the bare key and set it as SD_WORKER_API_KEY yourself.
Sites behind a VPN or machine-credential SSO
The panel also shows a command for System browser mode. Instead of a headless browser in a container, the worker opens that machine's own Chrome with a dedicated profile, so the company VPN, device certificates and proxy settings all apply. Run it on the machine that has VPN access, not inside Docker, and sign in to your VPN portal or SSO once in the window that opens. On a Mac, the desktop app does the same with one click.
Control what it can reach
Each worker has an Access setting:
- Allow all domains. The default. The worker may reach any host.
- Allow specific domains. Only the hosts you list, and their subdomains.
- Block specific domains. Any host except the ones you list, and their subdomains.
On a network where reach matters, switch to Allow specific domains and list only what actors need.
Remove a worker
Delete the worker from Workers. Actors assigned to it are unassigned and go back to the cloud browser. Then stop the container on your host:
docker rm -f sd-workerTroubleshooting
The worker stays Offline. Check the container is running
(docker ps) and read its logs (docker logs sd-worker). The host needs
outbound HTTPS to app.stuntdouble.io.
Test connection says "No response from worker. Is it running?" The worker has not checked in. Start the container, wait for Connected, then test again.
Test connection fails on your internal URL. The worker is up but cannot reach that host. Check DNS and routing from the host, and the worker's Access setting.
You lost the API key. It is only shown once. Delete the worker and create a new one.
Settings shows "Enterprise feature". Workers need the Enterprise plan. Contact us to upgrade.