<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Macos 14 Agent Console App on RockB</title><link>https://baeseokjae.github.io/tags/macos-14-agent-console-app/</link><description>Recent content in Macos 14 Agent Console App on RockB</description><image><title>RockB</title><url>https://baeseokjae.github.io/images/og-default.png</url><link>https://baeseokjae.github.io/images/og-default.png</link></image><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 28 Sep 2026 19:07:40 +0000</lastBuildDate><atom:link href="https://baeseokjae.github.io/tags/macos-14-agent-console-app/index.xml" rel="self" type="application/rss+xml"/><item><title>herdrm Review: The Coding Agent Console macOS Users Were Missing</title><link>https://baeseokjae.github.io/posts/herdrm-macos-console-coding-agents/</link><pubDate>Mon, 28 Sep 2026 19:07:40 +0000</pubDate><guid>https://baeseokjae.github.io/posts/herdrm-macos-console-coding-agents/</guid><description>herdrm is a coding agent console for macOS and the herdr runtime: one sidebar for local and SSH agents, real PTYs, and a licence caveat.</description><content:encoded><![CDATA[<p>herdrm is a native macOS SwiftUI client for herdr, the Y Combinator-backed agent runtime. It puts every space, coding agent, and terminal from your local Mac and any SSH device into a single sidebar, and clicking a row attaches the real agent PTY. It is a console, not an engine: it owns no terminals, and it does nothing without a herdr server behind it.</p>
<h2 id="is-herdrm-a-coding-agent-console-on-macos-or-just-a-window-onto-one">Is herdrm a coding agent console on macOS, or just a window onto one?</h2>
<p>The single most important thing to understand about herdrm is that it does not run agents. It renders them.</p>
<p>Every row you see in the sidebar comes off a Unix socket as newline-delimited JSON frames. herdrm holds no state that the herdr runtime does not already own. That architectural choice produces a failure model most agent UIs do not have: if herdrm crashes, your agents keep running, because the runtime never depended on the console. If herdr crashes, the work stops, and no amount of restarting herdrm brings it back.</p>
<p>Zentor&rsquo;s review of the app framed this as &ldquo;a console, not an engine,&rdquo; and it is the cleanest way to describe it. The feature list reads like a window manager rather than an agent product precisely because the console is downstream of everything. Status, layout, session identity — all of it belongs to herdr. herdrm decides how it looks, not what it means.</p>
<p>That distinction matters economically too. herdrm is free-ish software rendering an Apache-2.0 runtime. If you evaluate only the Mac app, you are evaluating the smallest and least consequential piece of the stack.</p>
<table>
  <thead>
      <tr>
          <th>Layer</th>
          <th>What it is</th>
          <th>Licence</th>
          <th>Fails as</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>herdr</td>
          <td>Rust agent runtime, background server, local socket API, TUI built in</td>
          <td>Apache 2.0</td>
          <td>Agents stop; the whole workflow halts</td>
      </tr>
      <tr>
          <td>herdrm</td>
          <td>SwiftUI macOS console that attaches to herdr sockets</td>
          <td>PolyForm Noncommercial 1.0.0</td>
          <td>You lose the view; agents keep working</td>
      </tr>
      <tr>
          <td>Agents (Claude Code, Codex, Cursor Agent, and others)</td>
          <td>Real CLI processes owning real terminal panes</td>
          <td>Vendor-specific</td>
          <td>Only that pane is affected</td>
      </tr>
  </tbody>
</table>
<h2 id="how-does-herdrm-talk-to-herdr-and-why-does-that-matter-over-ssh">How does herdrm talk to herdr (and why does that matter over SSH)?</h2>
<p>herdrm connects to a herdr socket, and it treats a remote socket exactly like a local one. Remote sockets ride the normal OpenSSH path — typically <code>ssh -L</code> forwarding to the herdr daemon running on the far machine — with authentication handled by your OpenSSH config and agent, Tailscale SSH, or a password stored in the macOS Keychain. Because the transport is forwarding a Unix socket rather than inventing a second remote protocol, local and remote devices behave identically in the UI.</p>
<p>The practical consequence is the honest setup story: herdrm aggregates hosts but provides none. If you want an agent running at 3 a.m. on a machine that is not your laptop, that machine has to exist and stay awake — a VPS, a home server, a workbox that is always on. The Mac becomes the window, not the workspace. That connects directly to the always-on-agent pattern: the console is what makes it observable, not what makes it possible.</p>
<p>The app is also not Electron. It is a SwiftUI app with an embedded terminal engine, and the repository&rsquo;s language breakdown tells you something the marketing copy does not: on 2026-09-28, <code>missuo/herdrm</code> is 79.4% C and 19.9% Swift. The C share is the vendored libghostty (Ghostty) terminal engine, which arrived in the 0.6.x line; the README&rsquo;s architecture diagram still names SwiftTerm, which is documentation drift rather than a bug. Third-party coverage from August 2026 that reported the repo as &ldquo;99.8% Swift&rdquo; is describing a version of the project that no longer exists.</p>
<h2 id="what-is-actually-in-the-console">What is actually in the console?</h2>
<p>The sidebar is organised into spaces, agents, and terminals. Each device gets an OS badge and a tint, there is a device filter in the bottom-left corner, a <code>Cmd-K</code> search for jumping to a pane, notifications, and a live terminal view. Selecting a row runs the equivalent of <code>herdr agent attach</code> and drops you into the real PTY — no chat wrapper, no re-serialised transcript, no lossy tool-call rendering.</p>
<p>Status states are the part people trust too much. herdr decides whether an agent is running, waiting, or blocked; herdrm only renders that decision. Per the herdr agent documentation, state authority is layered: when an integration is installed (Pi, OMP, Kimi Code, MastraCode, OpenCode/Kilo via plugin), lifecycle hooks report state directly. When it is not, herdr falls back to a screen manifest — which is the path Claude Code, Codex, Cursor Agent, Copilot CLI, Grok, Antigravity, and Kiro take. Gemini CLI and Cline are detected but documented as less thoroughly tested. A screen-manifest agent can take several seconds to register a blocked prompt, and an agent that gets stuck in a way the manifest does not recognise can keep looking busy. Green dots are a hint, not ground truth.</p>
<h2 id="why-does-a-real-terminal-beat-a-chat-wrapper-for-coding-agents">Why does a real terminal beat a chat wrapper for coding agents?</h2>
<p>Because the workflows coding agents produce are not chat-shaped.</p>
<p>When Claude Code prints a diff, asks a permission question with a numbered menu, or opens a TUI of its own for a long-running plan, a chat-shaped client has to either emulate that UI or strip it. herdrm does neither: you get the actual pane, with shell history, logs, and running processes intact, and state rolls up from pane to tab to workspace. The same fidelity is why people keep diff viewers and pagers inside the agent session at all — they are readable only at real terminal width.</p>
<p>The cost of fidelity is that you inherit the terminal&rsquo;s own problems. One documented example: from 0.6.2 onward, every opened agent stayed mounted at zero opacity, so busy background agents kept drawing full-window Metal frames and typing in the visible pane lagged — worst over SSH and in large windows. It was fixed in 0.6.9 by telling Ghostty that hidden panes are occluded (issue #95). That is a real regression introduced and fixed inside a single minor line, which is what early-stage software looks like.</p>
<h2 id="what-defaults-should-you-change-before-you-start">What defaults should you change before you start?</h2>
<p>The most consequential default in herdrm is one you should change on day one or consciously accept.</p>
<p>The New Agent picker enables each agent&rsquo;s own bypass-permissions flag by default. For Claude Code, that is <code>--dangerously-skip-permissions</code>. The maintainer&rsquo;s justification is coherent: detached agents run unattended, so a permission prompt that nobody answers is a dead end, and a console built around background sessions cannot afford dead ends. But the tradeoff is real, and it is not just a convenience footnote. An agent started that way will not stop to ask before it writes files, runs commands, or pushes.</p>
<p>A workable rule set:</p>
<ul>
<li>Keep bypass-permissions on only for agents running in a scratch or container-like workspace with no production credentials on the path.</li>
<li>Turn it off for any agent with access to a real repository, cloud credentials, or a production SSH key.</li>
<li>Never enable it for an agent on a machine you share with other people or workloads.</li>
<li>Audit the notification settings at the same time; unattended agents are safe only if something is watching for the states you actually care about.</li>
</ul>
<h2 id="how-do-you-install-herdrm-without-falling-for-the-impersonation-site">How do you install herdrm without falling for the impersonation site?</h2>
<p>herdrm has no official website. That sentence is not trivia — it is the reason a supply-chain incident happened in this project&rsquo;s name.</p>
<p>In 2026, a GitHub Pages site impersonating herdrm distributed a Windows payload (<code>zen.exe</code>, <code>Application.bat</code>, <code>key.txt</code>) under the herdrm brand. The maintainer confirmed in issue #86 that the only official sources are the GitHub repository <code>missuo/herdrm</code> and the Homebrew cask <code>owo-network/brew/herdrm</code>, and that genuine builds are signed by MOE AI LLC and notarised. If you install from anywhere else, you are trusting an unknown binary with your development machine.</p>
<p>The legitimate install path is short. The runtime first, on the Mac and on every remote box:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -fsSL https://herdr.dev/install.sh | sh
</span></span></code></pre></div><p>Then the console:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew install owo-network/brew/herdrm
</span></span></code></pre></div><p>Alternatively, unzip the release into <code>/Applications</code>. herdrm requires macOS 14 or later and ships as a universal binary (Apple Silicon and Intel) with Sparkle auto-updates. There is no CI gate to point at, and the release cadence is aggressive: the project went public on 2026-08-19 and shipped v0.6.9 on 2026-09-23, with 37 documented versions in <code>CHANGELOG.md</code> in roughly five weeks. As of 2026-09-28 the repository shows 721 stars, 60 forks, 10 open issues, 204 commits, and 22 contributors, with 66 pull requests and 37 issues opened in total. Downloads across the last ten releases stand at 5,333 (13,131 across all 37 releases), of which <code>herdrm-0.6.9.zip</code> accounts for 305 and the Sparkle <code>appcast.xml</code> for 1,321 hits.</p>
<table>
  <thead>
      <tr>
          <th>Signal</th>
          <th>Value (2026-09-28)</th>
          <th>What it tells you</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Stars / forks / contributors</td>
          <td>721 / 60 / 22</td>
          <td>Small, real, and actively contributed to</td>
      </tr>
      <tr>
          <td>Commits / public since</td>
          <td>204 / 2026-08-19</td>
          <td>Five weeks of history, no long track record</td>
      </tr>
      <tr>
          <td>Latest release</td>
          <td>v0.6.9 (2026-09-23)</td>
          <td>37 versions in the changelog</td>
      </tr>
      <tr>
          <td>Release downloads (all 37)</td>
          <td>13,131</td>
          <td>Installed base is small in absolute terms</td>
      </tr>
      <tr>
          <td>Language mix</td>
          <td>79.4% C, 19.9% Swift</td>
          <td>Vendored Ghostty engine, not a pure Swift app</td>
      </tr>
  </tbody>
</table>
<h2 id="is-herdrm-free-for-commercial-use-or-do-teams-need-a-licence">Is herdrm free for commercial use, or do teams need a licence?</h2>
<p>herdrm is licensed under PolyForm Noncommercial 1.0.0. In practice: free to use, modify, and share for any noncommercial purpose; commercial use requires a separate licence from the maintainer. GitHub&rsquo;s licence API still reports the repository as &ldquo;Other/NOASSERTION&rdquo; because PolyForm is not one of GitHub&rsquo;s recognised licences, so a casual scan of the repo sidebar will not tell you what you are agreeing to.</p>
<p>The history is instructive. Issue #67 was opened asking for a licence at a point when the repository had none — source-available but under default copyright. The maintainer replied that no LICENSE file means default copyright, and that a licence was being chosen &ldquo;because it interacts with upcoming product plans.&rdquo; PolyForm landed; a follow-up question in the same thread about what &ldquo;noncommercial&rdquo; actually means for ordinary company work remains open.</p>
<p>For an individual developer this is a non-issue. For a team, it is the sentence to read before you install: the runtime underneath is Apache 2.0, and the console on top is not free at work. Test it as &ldquo;the free runtime, the free console, the not-free-at-work app.&rdquo;</p>
<h2 id="how-does-herdrm-compare-with-waku-cmux-bessie-and-heeler">How does herdrm compare with Waku, cmux, Bessie and Heeler?</h2>
<p>herdrm is one client in a young ecosystem, and the ecosystem is growing far faster than the runtime&rsquo;s feature set. herdr itself sits at 41,234 stars and 3,168 forks with 370 open issues, last pushed 2026-09-28, and its latest stable release v0.9.1 (2026-09-16) has pulled 158,102 asset downloads. The project site claims 40,432 GitHub stars, 1,046,795 installs, 1,324 community plugins, 22 detected agent CLIs, and carries a &ldquo;$6M raised&rdquo; banner. Note the licence churn underneath the app you are reviewing: a July 2026 comparison article listed herdr as AGPL-3.0, while the live site now states Apache 2.0 — the runtime relicensed during the summer.</p>
<table>
  <thead>
      <tr>
          <th>Tool</th>
          <th>What it is architecturally</th>
          <th>Platform</th>
          <th>Licence</th>
          <th>Stars</th>
          <th>Best for</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>herdrm</td>
          <td>Client for a herdr socket; owns no terminals</td>
          <td>macOS 14+</td>
          <td>PolyForm Noncommercial 1.0.0</td>
          <td>721</td>
          <td>Multi-machine herdr users who want one window</td>
      </tr>
      <tr>
          <td>herdr TUI</td>
          <td>The runtime&rsquo;s own interface, built in</td>
          <td>macOS, Linux, Windows</td>
          <td>Apache 2.0</td>
          <td>41,234</td>
          <td>Staying where the work happens</td>
      </tr>
      <tr>
          <td>Waku</td>
          <td>Standalone native Mac harness that drives agent CLIs itself</td>
          <td>macOS, Linux, Windows</td>
          <td>GPL-3.0</td>
          <td>1,543</td>
          <td>Native app without a runtime dependency</td>
      </tr>
      <tr>
          <td>cmux</td>
          <td>Ghostty-based macOS terminal app with vertical tabs, notifications and a control CLI</td>
          <td>macOS</td>
          <td>GPL-3.0-or-later (server/relay components under BSL 1.1)</td>
          <td>27,470</td>
          <td>A terminal-first composable workspace, not a herdr console</td>
      </tr>
      <tr>
          <td>Bessie</td>
          <td>Mac client bundling herdr 0.8.0 and libghostty</td>
          <td>macOS</td>
          <td>Apache 2.0</td>
          <td>11</td>
          <td>A lighter, permissive alternative client</td>
      </tr>
      <tr>
          <td>Heeler</td>
          <td>iOS client for herdr</td>
          <td>iOS 18+</td>
          <td>Apache 2.0</td>
          <td>430</td>
          <td>Attaching to agents from a phone</td>
      </tr>
  </tbody>
</table>
<p>The comparison that gets misstated most often is herdrm versus Waku. They look similar — both have a sidebar of agents — because herdrm borrowed Waku&rsquo;s sidebar idiom. But Waku drives the agent CLIs itself, normalising each one over its strongest native interface (stream-json, JSON-RPC, live events) into a provider-neutral model, with prompt checkpoints that stash the working tree under a hidden git ref so code and conversation roll back together. Waku is local by architecture: no account, no telemetry, no cloud in the middle, GPL-3.0, v0.1.19 released 2026-09-10. herdrm is explicitly &ldquo;not Waku&rdquo;: it consumes a herdr socket and hands you the pane.</p>
<p>The strategic risk worth naming: since herdrm is a third-party client and the runtime ships its own TUI, an official Mac client landing inside herdr would change herdrm&rsquo;s calculus overnight.</p>
<p>That also frames the &ldquo;herdr vs herdrm&rdquo; question correctly. herdrm is not an alternative to herdr and it is not a competing runtime — it is the herdr Mac client. Anyone searching for a herdrm alternative because they dislike attach-based clients is really searching for a different runtime, and the honest answers there are Waku (own sessions) or a plain terminal multiplexer with no agent awareness at all.</p>
<h2 id="what-actually-breaks-in-practice-and-who-should-install-herdrm">What actually breaks in practice, and who should install herdrm?</h2>
<p>Four failure modes are documented rather than hypothetical.</p>
<p>First, status latency. Hook-based agents report instantly; screen-manifest agents lag by seconds, and a genuinely stuck agent can still render as busy. Do not use the sidebar as your only signal that a long run is healthy.</p>
<p>Second, remote latency. Over SSH the terminal is only as responsive as the link, and the 0.6.2–0.6.9 occlusion bug hit hardest exactly there.</p>
<p>Third, identity persistence is weaker than layout persistence. A kill -9 test of the runtime found the layout — panes, tabs, working directories — came back, but the registered agent record dropped from one to zero and every terminal ID changed. If your tooling keys off terminal IDs across a crash, it will break.</p>
<p>Fourth, the licence and the platform. It is Mac-only, and it is not free for commercial use.</p>
<p>Install herdrm if you already run herdr across more than one machine, want a single window over local and remote agents, and are comfortable living one step behind the runtime&rsquo;s releases. Stay on the herdr TUI if you work on one machine, read changelogs closely, or need a permissive licence at work — that path is Apache 2.0 and always in sync. And if you want a native Mac app that owns its own sessions rather than attaching to a runtime, Waku is the honest alternative, with a different licence and a different philosophy.</p>
<h2 id="faq">FAQ</h2>
<h3 id="is-herdrm-a-coding-agent">Is herdrm a coding agent?</h3>
<p>No. herdrm contains no agent loop, no model calls, and no task execution. It is a client: it reads frames from a herdr socket, draws a sidebar, and attaches your Mac to terminal panes that herdr owns. You still need the agent CLIs themselves (Claude Code, Codex, Cursor Agent, and the rest) plus the herdr runtime.</p>
<h3 id="does-herdrm-work-without-herdr-installed">Does herdrm work without herdr installed?</h3>
<p>No, and this is the most common misconception. herdrm is useless without a herdr server reachable over a socket. Install herdr on the Mac and on every remote host first, verify the runtime is running, then add devices in the console. If herdr is down, the console has nothing to show.</p>
<h3 id="what-macos-version-does-herdrm-require-and-how-do-i-install-it">What macOS version does herdrm require, and how do I install it?</h3>
<p>macOS 14 or later, universal binary for Apple Silicon and Intel. The two official install paths are <code>brew install owo-network/brew/herdrm</code> or unzipping the release into <code>/Applications</code>. There is no official herdrm website; genuine builds are signed by MOE AI LLC and notarised. A GitHub Pages lookalike once distributed Windows malware under this name, so treat any other download page as hostile.</p>
<h3 id="can-i-use-herdrm-at-work">Can I use herdrm at work?</h3>
<p>Not without a commercial licence. herdrm is licensed under PolyForm Noncommercial 1.0.0, which permits noncommercial use, modification, and sharing, and requires a separate licence from the maintainer for commercial use. The herdr runtime underneath is Apache 2.0, which makes the split easy to miss. Check with whoever owns licence compliance before deploying it on a company machine.</p>
<h3 id="is-herdrm-safe-if-it-starts-agents-with-permissions-bypassed">Is herdrm safe if it starts agents with permissions bypassed?</h3>
<p>It is as safe as the workspace you point it at. The New Agent picker enables each agent&rsquo;s bypass-permissions flag by default — for Claude Code that is <code>--dangerously-skip-permissions</code> — so an agent will not stop to ask before writing files or running commands. Keep that default only for scratch workspaces with no production credentials or SSH keys on the path, and turn it off for anything else.</p>
]]></content:encoded></item></channel></rss>