Install on Linux
Use the official Debian, RPM or AppImage release package for x86_64 Linux.
Guides follow the current project source. Check the release notes for your installed version.
Verify the downloaded package
Download the package and checksum file from the same official release. Open a terminal in the folder containing your downloaded package and compute its SHA-256 hash.
Find that exact filename in RepoTunnel-SHA256SUMS.txt and compare the complete hash. Continue with installation only when they match.
sha256sum RepoTunnel_0.4.1_amd64.deb For the RPM or AppImage, replace the filename with the actual package you downloaded. A mismatch means the file should be downloaded again from the official release.
Debian / Ubuntu / Linux Mint
For Linux Mint, Ubuntu and other Debian-family x64 installations, download the official .deb from the v0.4.1 release and open it using the distribution's package installer. Alternatively, use your distribution's package manager on the downloaded local file.
sudo apt install ./RepoTunnel_0.4.1_amd64.deb Run this from the folder where you downloaded the .deb. Verify the package name and checksum first.
Fedora / RPM compatible
Use the official .rpm package from the release.
sudo dnf install ./RepoTunnel-0.4.1-1.x86_64.rpm AppImage
The AppImage is a portable Linux x64 option. After verifying the downloaded file, mark the AppImage executable and launch it as your normal user. It should not require exposing the MCP gateway to the network.
chmod +x RepoTunnel_0.4.1_amd64.AppImage
./RepoTunnel_0.4.1_amd64.AppImage Terminal sandbox requirement
AI terminal/process execution on Linux uses Bubblewrap and is intentionally unavailable if the required sandbox cannot be used. Install Bubblewrap with your distribution package manager if RepoTunnel reports that execution is unavailable.
First-run confirmation
Open RepoTunnel, confirm it displays its workspace UI, add one disposable development folder and inspect the status of the local gateway. If the UI opens but AI commands are refused, that may be the intended fail-closed sandbox behavior rather than a broken installation.