Quickstart
Create an environment, do work in it, checkpoint it, move it to another machine byte-identical, share it, and prove its history: all from the reeg CLI.
Zero-setup first look: open a live environment in the Console and click Verify independently. The full provenance verification runs in your browser from public Sui + Walrus data alone, with no wallet, no install, and no Reeg backend in the trust path.
Use testnet to run the whole loop. The full checkpoint → restore → verify path is proven end-to-end on testnet. On mainnet today, encryption, storage, anchoring, and offline verify work, but the decrypt step of a restore waits on a provider Seal key server.
Prerequisites
- Node ≥ 24, pnpm 10, Rust 1.95, the Sui CLI (1.73), and the Walrus CLI.
- A funded testnet address, a little testnet SUI (gas) and WAL (storage), with its Ed25519 key in your local Sui keystore (
~/.sui/sui_config/sui.keystore). On testnet both are free via the faucet andwalrus get-wal.
Install
There's no npm package yet: the CLI is built from the monorepo.
git clone <your-reeg-repo-url> reeg && cd reeg
corepack enable && corepack prepare pnpm@10.33.1 --activate
pnpm install
cargo build --manifest-path engine/Cargo.toml # builds the reeg-engine binary
pnpm -r build # builds the reeg CLI
If reeg isn't on your PATH afterward, run any command below as pnpm --filter @reeg/cli exec reeg <verb>.
Configure
REEG_ENGINE points at the engine binary; REEG_PACKAGE_ID and REEG_OPERATOR are required for every on-chain command.
export REEG_ENGINE="$PWD/engine/target/debug/reeg-engine" # absolute path (run from the repo root)
export REEG_NETWORK=testnet
export REEG_PACKAGE_ID=0x8f2faf0b89e248f498cb0bc4b0ef98511613c4d7884e8ce41f0bc255246ca1d2
export REEG_OPERATOR=<your testnet address>
Check your setup, then prove the loop
Two commands take the guesswork out of a first run:
reeg doctor # preflight: keystore, engine binary, funds, RPC reachability, encryption config
reeg selftest # prove the full loop from THIS machine in about a minute:
# create -> encrypted checkpoint -> byte-identical restore (memory included) -> verify -> retire
doctor names anything missing with a remedy; selftest runs the real code paths against the network and reports each step pass/fail. If selftest is green, everything below will work.
The loop
reeg create # mint a Machine you own -> <machineId>
reeg run <machineId> -- sh -c 'echo hi > note.txt' # do work; captured in the command log
reeg checkpoint <machineId> --epochs 1 # snapshot -> Seal-encrypt -> Walrus -> anchor on Sui
reeg restore <machineId> --dest /tmp/restored # rebuild the workdir byte-identically on any host
reeg grant <machineId> <address> --role restore # let another address decrypt and restore
reeg revoke <machineId> <address> # stop future decryption (forward-looking)
reeg fork <machineId> # child Machine, lineage recorded on chain
reeg verify <machineId> # verify the history offline — public Sui only, Reeg switched off
REEG_HOME (default ~/.reeg) holds the local working state for a machine. Point it at a different directory to act as a separate "host". Restoring into a fresh REEG_HOME is how you prove a checkpoint comes back on a machine that never saw it.
Run the whole story at once
The end-to-end acceptance test creates and checkpoints on one host, deletes it, restores byte-identically on a fresh host, verifies offline, shares to a second address that restores, then revokes, across simulated hosts:
export REEG_OPERATOR=<funded testnet address>
export REEG_GRANTEE=<second funded testnet address>
export REEG_ENGINE="$PWD/engine/target/debug/reeg-engine" # must be absolute: pnpm runs the script from a sub-package dir
pnpm --filter @reeg/test run live:acceptance
Next
- CLI reference: every verb, flag, and environment variable.
- How it works: what happens at the commit boundary.