Agent skill

Buzz Self Hosting

by tonbistudio in tonbistudio/buzz-skills

A skill your agent uses when helping a user set up, debug, or operate a self-hosted Buzz relay through Docker Compose.

MITAuto-check: notesDevOps & Cloud

Install Buzz Self Hosting

skills CLI
$ npx skills add tonbistudio/buzz-skills --skill buzz-self-hosting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tonbistudio/buzz-skills buzz-self-hosting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tonbistudio/buzz-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/buzz-self-hosting .claude/skills/buzz-self-hosting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
buzz-self-hosting
GitHub stars
276
Token cost
~2.2k tokens
SKILL.md length
1,068 words
Files
2
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when helping a user set up, debug, or operate a self-hosted Buzz relay through Docker Compose.

  • Works in 6 steps: cd deploy/compose && cp .env.example… → Set the URL block (BUZZ_DOMAIN,… → ./run.sh config (validates; catches… → …
  • Helping a user set up
  • SKILL.md covers The mental model, Setup steps, Footgun: never use localhost… and Footgun: changing BUZZ_DOMAIN…, plus 5 more sections
  • Calls docker, curl and openssl; needs BUZZ_RELAY_PRIVATE_KEY and BUZZ_GIT_HOOK_HMAC_SECRET

What it does

Buzz Self Hosting is an agent skill from tonbistudio/buzz-skills. Use when helping a user set up, debug, or operate a self-hosted Buzz relay through Docker Compose. Do not use for general Docker questions or non-Buzz Nostr deployments.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `evals/evals.json`).

It sits in DevOps & Cloud, covering Containers and Deployment. It works with Docker and Git. The licence is MIT.

When your agent uses it

  • Helping a user set up
  • Operate a self-hosted Buzz relay through Docker Compose
  • General Docker questions
  • Non-Buzz Nostr deployments

Example prompts

  • “/buzz-self-hosting”

Requirements

  • Docker
  • A credential in BUZZ_RELAY_PRIVATE_KEY
  • A credential in BUZZ_GIT_HOOK_HMAC_SECRET

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. cd deploy/compose && cp .env.example .env, then edit .env
  2. Set the URL block (BUZZ_DOMAIN, RELAY_URL, BUZZ_MEDIA_BASE_URL, BUZZ_MEDIA_SERVER_DOMAIN, BUZZ_CORS_ORIGINS) — all derive from one host…
  3. ./run.sh config (validates; catches leftover CHANGE_ME), then ./run.sh start. TLS on a public domain: BUZZ_COMPOSE_TLS=true ./run.sh start.
  4. Liveness: curl -fsS http://127.0.0.1:3000/_liveness.
  5. Register members: ./run.sh add-member for every human and every agent, with sleep 1 between adds (same-second roster events collide)…
  6. Connect the desktop app with the exact RELAY_URL, create channels, add agents to channels, @mention.

What it can do on your machine

Read from SKILL.md and the folder at commit 3f2d570. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • curl
    • openssl
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BUZZ_RELAY_PRIVATE_KEY
    • BUZZ_GIT_HOOK_HMAC_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Buzz Self Hosting loads about 2.2k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 1,068 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:24
    1. `cd deploy/compose && cp .env.example .env`, then edit `.env`:
  • NoteMentions a .env fileSKILL.md:27
    entity. Set once, never rotate; back up `.env` itself.
  • NoteMentions a .env fileSKILL.md:55
    docker compose --env-file .env -f compose.yml logs relay --since 10m | grep '"Event ingested via pipeline"'
  • NoteMentions a .env fileSKILL.md:80
    - `$EDITOR .env` is a Unix-ism; PowerShell users should `notepad .env`.
  • NoteMentions a .env fileSKILL.md:81
    - A file named `.env` looks nameless in Explorer unless "File name extensions" is on.
  • NoteMentions a .env fileSKILL.md:86
    → MinIO console `:9001` (S3 creds from `.env`), Adminer `:8082` (server `postgres`, user `buzz`), Prometheus `:9090`. H
  • NoteMentions a .env fileSKILL.md:87
    ata is local: `docker compose --env-file .env -f compose.yml exec -T postgres psql -U buzz -d buzz -c "SELECT kind, left
  • NoteMentions a .env fileSKILL.md:95
    copy .env <backup-dir>\env-backup.txt
  • NoteMentions a .env fileSKILL.md:96
    docker compose --env-file .env -f compose.yml exec -T postgres pg_dump -U buzz buzz > <backup-dir>\buzz-db.sql
  • NoteMentions a .env fileSKILL.md:101
    `.env` is part of the backup — restoring data volumes without its keys restores nothing.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tonbistudio/buzz-skills at commit 3f2d570, republished under its MIT licence (© tonbistudio). 1,068 words, ~2,247 tokens.

Download SKILL.mdSave it as .claude/skills/buzz-self-hosting/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
buzz-self-hosting
description
Use when helping a user set up, debug, or operate a self-hosted Buzz relay through Docker Compose. Do not use for general Docker questions or non-Buzz Nostr deployments.
version
1.0.0

Buzz Self-Hosting Guide

Walk the user through standing up their own buzz-relay with the Docker Compose stack in deploy/compose/, and debug it layer by layer when agents or clients misbehave. Every footgun in here was hit in a real setup; check them before inventing new theories.

Guide, don't drive: give the user paste-ready commands and let them run anything that changes state. Verify results yourself with read-only checks (logs, rosters, queries).

The mental model

  • One relay = one community. The relay URL IS the community. The relay routes connections to a community by the exact hostname in BUZZ_DOMAIN. A connection with any other Host gets 404 on the WebSocket upgrade — this looks like "relay is down" but isn't.
  • The stack is: relay + Postgres (events, search, memberships) + MinIO (media + git packfiles) + Redis (pub/sub only, nothing durable) + a git volume.
  • On a closed relay (RELAY_OWNER_PUBKEY set, BUZZ_REQUIRE_RELAY_MEMBERSHIP=true), everything that connects — humans AND agents — must be in the relay member roster.

Setup steps

  1. cd deploy/compose && cp .env.example .env, then edit .env:
    • Secrets are all generated/invented locally. Nothing comes from a portal. openssl rand -hex 32 for BUZZ_RELAY_PRIVATE_KEY and BUZZ_GIT_HOOK_HMAC_SECRET; invent Postgres/Redis/S3 passwords (Compose creates those services with whatever you set).
    • RELAY_OWNER_PUBKEY = the user's own pubkey, 64-char hex, from their Buzz Desktop profile. Footgun: this var has no BUZZ_ prefix — easy to miss among neighbors that all do.
    • BUZZ_RELAY_PRIVATE_KEY is the relay's identity. Set once, never rotate; back up .env itself.
    • Pin BUZZ_IMAGE to a release tag for anything long-lived; :main moves daily.
  2. Set the URL block (BUZZ_DOMAIN, RELAY_URL, BUZZ_MEDIA_BASE_URL, BUZZ_MEDIA_SERVER_DOMAIN, BUZZ_CORS_ORIGINS) — all derive from one host choice. See the localhost footgun below before choosing.
  3. ./run.sh config (validates; catches leftover CHANGE_ME), then ./run.sh start. TLS on a public domain: BUZZ_COMPOSE_TLS=true ./run.sh start.
  4. Liveness: curl -fsS http://127.0.0.1:3000/_liveness.
  5. Register members: ./run.sh add-member <pubkey> for every human and every agent, with sleep 1 between adds (same-second roster events collide). Verify with ./run.sh list-members.
  6. Connect the desktop app with the exact RELAY_URL, create channels, add agents to channels, @mention.

Footgun: never use localhost for a local relay — use 127.0.0.1 everywhere

buzz-core::relay::normalize_relay_url rewrites every loopback host to 127.0.0.1 (localhost, ::1). The desktop app runs each managed agent's relay URL through it before spawning the harness. The relay, however, routes by the literal BUZZ_DOMAIN. Result with BUZZ_DOMAIN=localhost: the app itself connects fine (its own HTTP client doesn't rewrite the Host header) but every agent harness gets 404 and exits code 1. The app UI offers no way around it — the per-agent relay_url field is deliberately ignored (agents always inherit the active workspace relay).

Therefore: for local deployments set BUZZ_DOMAIN=127.0.0.1 and use ws://127.0.0.1:3000 in the app and everywhere else. Real public domains are unaffected.

Diagnostic — test the host routing directly (101 = good, 404 = wrong host):

bash
curl -s -o /dev/null -w "%{http_code}\n" -H "Connection: Upgrade" -H "Upgrade: websocket" \
  -H "Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==" -H "Sec-WebSocket-Version: 13" http://<host>:3000/

Footgun: changing BUZZ_DOMAIN re-keys the community

The relay ensures its deployment community keyed to the host (Deployment community ensured, host=... in relay logs). Change the domain → restart → a fresh empty community. The desktop app will keep showing the old community's channels and member lists from cache — messages even still send (kind 9) — but channel records (39000/39002, 9007/9000) don't exist relay-side, so agents discover 0 channels no matter what the UI shows.

Fix: in the app, remove the community entirely and re-add it, then create channels fresh. Verify server-side, not in the UI:

bash
docker compose --env-file .env -f compose.yml logs relay --since 10m | grep '"Event ingested via pipeline"'

Channel creation must produce kind 9007/40100 events; adding a member to a channel produces kind 9000. If the user "did it in the app" but those kinds never arrive, the app state is stale — clean re-add.

Show full SKILL.md (481 more words)Show less

Debugging agents that don't respond — check layers in this order

Agent harness logs: %APPDATA%\xyz.block.buzz.app\agents\logs\<agent-pubkey>__<relay-hash>.log (Windows). Read the newest run — stale error banners in the app UI often describe an old failure.

Log symptomLayerFix
relay connect failed ... 404 Not Found, exit 1Hostname routing127.0.0.1 everywhere (see above)
Connects, but roster (list-members) lacks the agentRelay membership./run.sh add-member <agent-pubkey>
discovered 0 channel(s) — agent will sit idleChannel membershipAdd agent to a channel; verify a kind-9000 event lands; if UI says it's added but log still says 0 → stale community state, clean re-add
discovered 1 channel(s) + subscribed, mention ignoredrespond_toDefault is owner-only; only the owner's mentions wake it
Wakes but errors instead of replyingModel authPer-runtime credentials (Hermes setup, Claude login, OpenAI key) — plumbing is fine

Agent pubkeys and (plaintext!) private keys live in %APPDATA%\xyz.block.buzz.app\agents\managed-agents.json — treat as sensitive. The entries with private_key_nsec are the runtime records.

A healthy sequence in the harness log: connected to relay → discovered N channel(s) → subscribed to channel <uuid>; live adds show membership notification: subscribing to new channel.

Windows-specific footguns

  • ./run.sh is bash. In PowerShell it opens the file in an editor instead of running. Use Git Bash (/d/path style paths) or bash run.sh.
  • Git Bash mangles container paths: docker compose exec relay /usr/local/bin/buzz-admin ... becomes C:/Program Files/Git/usr/local/bin/... and fails with "OCI runtime exec failed". Fix: export MSYS_NO_PATHCONV=1 first, or run docker commands from PowerShell.
  • $EDITOR .env is a Unix-ism; PowerShell users should notepad .env.
  • A file named .env looks nameless in Explorer unless "File name extensions" is on.
  • If the app won't launch, check for hung instances: Get-Process buzz-desktop, buzz-acp — multiple Not-Responding buzz-desktop processes block new launches. Kill them all: Get-Process buzz-desktop, buzz-acp -ErrorAction SilentlyContinue | Stop-Process -Force.

Verification & inspection

  • Base stack exposes only relay port 3000. Admin surfaces need the dev overlay: BUZZ_COMPOSE_DEV=true ./run.sh start → MinIO console :9001 (S3 creds from .env), Adminer :8082 (server postgres, user buzz), Prometheus :9090. Home machines only — the overlay also publishes Postgres and Redis.
  • Prove data is local: docker compose --env-file .env -f compose.yml exec -T postgres psql -U buzz -d buzz -c "SELECT kind, left(content,60) FROM events WHERE kind=9 ORDER BY created_at DESC LIMIT 5;"
  • Postgres = the record (events partitioned by month, mention index, FTS, audit log, rosters). MinIO = media (content-addressed SHA-256) + git packfiles. Redis = disposable.

Backups

Volumes live inside Docker Desktop's WSL2 disk — not browsable, not backed up until dumped to real files:

powershell
copy .env <backup-dir>\env-backup.txt
docker compose --env-file .env -f compose.yml exec -T postgres pg_dump -U buzz buzz > <backup-dir>\buzz-db.sql
docker run --rm -v buzz-prod_buzz-minio-data:/data -v <backup-dir>:/backup alpine tar czf /backup/minio-data.tar.gz -C /data .
docker run --rm -v buzz-prod_buzz-git-data:/data -v <backup-dir>:/backup alpine tar czf /backup/git-data.tar.gz -C /data .

.env is part of the backup — restoring data volumes without its keys restores nothing.

Hosted → self-hosted migration

There is no export tool. Identity keypairs carry over (same person everywhere); agent definitions are local files; git repos migrate fully (clone from hosted, push to new relay). Channel history, DMs, media, canvases do not. A new relay starts empty — set expectations before the user tears anything down, and don't remove hosted communities until anything worth keeping (repos, archives via buzz messages get) is pulled.

© tonbistudio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in buzz-self-hosting of tonbistudio/buzz-skills.

  • SKILL.md
  • evals/evals.json

Open the folder on GitHubat commit 3f2d570

Compare with similar skills

Buzz Self Hosting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Buzz Self Hosting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Buzz Self Hosting this skilltonbistudio/buzz-skills276—~2.2kAutomated safety check: NotesMIT
Demo Local Rolloutcarverauto/serviceradar921—~4.2kAutomated safety check: PassApache-2.0
Releasear-io/ar-io-node127—~4.2kAutomated safety check: NotesAGPL-3.0
Medusa Cloud Local Buildmedusajs/medusa-agent-skills228—~1kAutomated safety check: NotesNone
Deploy To Tempsgotempsh/temps828—~1.3kAutomated safety check: NotesApache-2.0
Perplexity Server DeployescapeWu/perplexity-ai170—~662Automated safety check: NotesMIT

Similar skills

  • Demo Local Rollout

    carverauto/serviceradar

    Build unpublished sha-... An agent skill from carverauto/serviceradar.

    921 GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Release

    ar-io/ar-io-node

    Drive the AR.IO Node release process end-to-end — preflight checks, prepare commit, finalize with image SHAs, test docker compose profiles, tag & publish, and post-release cleanup.

    127 GitHub stars~4.2k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Medusa Cloud Local Build

    medusajs/medusa-agent-skills

    Reproduces a Medusa Cloud build on your machine with mcloud local build, to debug build-failed deployments without pushing or waiting on Cloud.

    228 GitHub stars~1k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Deploy To Temps

    gotempsh/temps

    Deploy applications to the Temps platform with automatic framework detection, Dockerfile generation, and container orchestration.

    828 GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Perplexity Server Deploy

    escapeWu/perplexity-ai

    Deploys the perplexity-ai project to its production server by pushing main, fast-forwarding the server checkout, rebuilding the image there and verifying health.

    170 GitHub stars~662 tokensUpdated 12 days ago
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from tonbistudio/buzz-skills

  • Hermes In Buzz

    tonbistudio/buzz-skills

    A skill your agent uses when connecting a remote Hermes gateway to Buzz end-to-end.

    276 GitHub stars~4.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • Buzz Media Attachments

    tonbistudio/buzz-skills

    A skill your agent uses when attaching a local media file to the active Buzz conversation.

    276 GitHub stars~1k tokensUpdated 2 mo ago
    Auto-check: notes

Works with

Categories

Questions about Buzz Self Hosting

What does Buzz Self Hosting do?

A skill your agent uses when helping a user set up, debug, or operate a self-hosted Buzz relay through Docker Compose. Buzz Self Hosting is an agent skill from tonbistudio/buzz-skills. Use when helping a user set up, debug, or operate a self-hosted Buzz relay through Docker Compose.

When should I use Buzz Self Hosting?

Buzz Self Hosting fits situations like: helping a user set up; operate a self-hosted Buzz relay through Docker Compose; general Docker questions; non-Buzz Nostr deployments.

How do I install Buzz Self Hosting in Claude Code?

Run `npx skills add tonbistudio/buzz-skills --skill buzz-self-hosting -a claude-code`. Or copy the skill folder (buzz-self-hosting in tonbistudio/buzz-skills) into .claude/skills/buzz-self-hosting in your project. Claude Code loads it when a task matches its description.

How do I install Buzz Self Hosting in Codex?

Run `npx skills add tonbistudio/buzz-skills --skill buzz-self-hosting -a codex`. Or copy the skill folder (buzz-self-hosting in tonbistudio/buzz-skills) into .agents/skills/buzz-self-hosting in your project. Codex loads it when a task matches its description.

Can I use Buzz Self Hosting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tonbistudio/buzz-skills --skill buzz-self-hosting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/buzz-self-hosting, .gemini/skills/buzz-self-hosting, .github/skills/buzz-self-hosting and .opencode/skills/buzz-self-hosting in your project.

What does Buzz Self Hosting need to run?

Going by SKILL.md and its folder, Buzz Self Hosting needs the command-line tools its instructions call (docker, curl, openssl and bash) and credentials named BUZZ_RELAY_PRIVATE_KEY and BUZZ_GIT_HOOK_HMAC_SECRET. Our summary lists: Docker; A credential in BUZZ_RELAY_PRIVATE_KEY; A credential in BUZZ_GIT_HOOK_HMAC_SECRET.

Does Buzz Self Hosting access the network?

SKILL.md contains no URLs. Its commands use docker and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Buzz Self Hosting safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Buzz Self Hosting use?

Buzz Self Hosting is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Buzz Self Hosting use?

About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Buzz Self Hosting?

Skills that share tags, products or a category with Buzz Self Hosting: Demo Local Rollout (carverauto/serviceradar, 921 stars), Release (ar-io/ar-io-node, 127 stars), Medusa Cloud Local Build (medusajs/medusa-agent-skills, 228 stars) and Deploy To Temps (gotempsh/temps, 828 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Buzz Self Hosting?

tonbistudio (a GitHub user) maintains it in tonbistudio/buzz-skills, which has 276 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on August 5, 2026.

Source: tonbistudio/buzz-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.