System Requirements
Use these requirements to size the control plane and every worker host before installation.
Hardware
Hardware needs scale with repository size, active worktrees, local model use, and configured concurrency; the values below are initial planning baselines, not hard limits.
| Component | Minimum | Recommended |
|---|---|---|
| CPU | 2 cores | 4+ cores (more if you run many parallel sessions) |
| RAM | 4 GB | 8+ GB |
| Disk | 10 GB free | 50+ GB free (scales with concurrent sessions and repository size) |
Disk usage scales with the number of concurrent sessions, plans, round tables, and merges — each gets its own working copy of every workspace repository under StoragePath. Each concurrent session also runs the agent's commands (builds, tests) on its host, so size CPU and RAM for your heaviest build multiplied by the host's session limit.
Software
Install these dependencies on the control-plane host and on each worker that executes the related workload.
| Requirement | Version | Notes |
|---|---|---|
| .NET Runtime (ASP.NET Core) | 10.0+ | Runs the server, Session Worker, and Deployment Worker |
| Git | 2.29+ | Required on every host that runs sessions or deployments |
| OS | Windows 10/11, Windows Server 2019+, Linux (containers) | Windows Service deployment is the recommended path on Windows |
| Script runtimes | As used by your hooks, tasks, and deploy templates | Bash, PowerShell, Node.js, or Python on the hosts that run them |
On Windows, the install script checks the OS, hardware minimums, free disk, and network path to the server, and installs the .NET 10 Hosting Bundle and Git for Windows when they are missing. Script runtimes for hooks and deploy templates are not installed; Git for Windows provides Bash.
Agent and models
Model requirements apply to every host eligible to run sessions with that model.
The built-in Polygent Code agent runs every session — no agent install is required. You pick a model and supply its credentials.
- API models need the provider API key, saved once in Backend Connections and delivered to every session host.
- Command-line models need the corresponding coding tool installed on
PATHand signed in as the service account on every eligible session host. See Local command-line models.
Database
The database stores platform state; choose one provider before production rollout and back it up independently of file storage.
Polygent supports three database providers, configured via appsettings.json:
| Provider | Use Case |
|---|---|
| SQLite | Default, zero-configuration, suitable for small teams and trials |
| PostgreSQL | Recommended for production with multiple users |
| SQL Server | Enterprise environments with existing SQL Server infrastructure |
See the Database configuration guide.
Network
Allow only the inbound and outbound paths required by your deployment, and terminate TLS before exposing Polygent to users.
| Direction | From → To | Purpose |
|---|---|---|
| Inbound (HTTPS, WebSocket) | Users and workers → server | Web client, API, live updates, worker connections. The server listens on http://localhost:5000 by default (8080 in the container); publish it through a TLS reverse proxy. |
| Outbound (HTTPS) | Server → identity provider | Sign-in and discovery. |
| Outbound (HTTPS) | Every session host → model providers | Model API calls for the models you allow. |
| Outbound (HTTPS) | Server and every session and deployment host → Git hosts | Clone, fetch, push, and pull requests. |
| Outbound (HTTPS) | Server → GitHub / Azure DevOps APIs | Ticket sync and pull-request tracking (optional). |
| Outbound (HTTPS) | Session hosts → server /mcp | Built-in agent tools. |
| Outbound (HTTPS) | Session hosts → your MCP servers | Optional external agent tools. |
Workers only connect outbound; no inbound port is needed on a worker host.
Authentication
Production deployments require one configured OAuth2 or OpenID Connect identity provider.
Polygent supports the following sign-in methods (GitHub is not a sign-in provider):
- Google OAuth2
- Microsoft OAuth2 (Microsoft 365 / Entra ID)
- Generic OpenID Connect — any OIDC-compliant IdP (Okta, Auth0, Keycloak, etc.)
Configure the provider in the Login section of appsettings.json. Sign-in cookies are always Secure, so users must reach Polygent over HTTPS. See Authentication.
Browser support
Use a current browser with cookies and WebSockets enabled.
The client targets evergreen browsers:
| Browser | Minimum |
|---|---|
| Chrome | 111+ |
| Edge | 111+ |
| Firefox | 128+ |
| Safari | 16.4+ |
WebSockets must be allowed end-to-end for live updates.
Optional integrations
Install or permit these integrations only when the corresponding feature is enabled.
| Integration | Use Case |
|---|---|
| GitHub PAT | Issue sync, issue creation, pull-request creation and tracking |
| Azure DevOps PAT | Work item sync, PR/MR creation and tracking |
| Session Worker host(s) | Spread AI sessions across multiple machines |
| Deployment Worker host(s) | Run slot deployments on dedicated machines |
| External MCP servers | Additional agent tools reachable from session hosts |
Security:
/mcpis authenticated with temporary per-run credentials, but it is an internal agent surface. Allow it only from the server and Session Worker networks and block it at the edge on internet-exposed installations. See MCP Server → Security boundary.