LiveHQ documentation
From first install to a healthy public app.
Task-based guidance for running trusted applications and databases on your Mac — without opening an inbound port.

The shortest path
Five moments to Live.
Each transition is visible. LiveHQ does not publish until the image, runtime, health, and exact route agree.
Install
Download the signed app and drag it into Applications.
Prepare
Verify Docker Desktop, enroll the Mac, and start the signed runtime.
Deploy
Choose a trusted folder or repository and review the exact plan.
Publish
Wait for health and the outbound OriginLink route to become Live.
Operate
Use logs, metrics, databases, privacy, domains, updates, and the CLI.
All guides
Learn by doing.
Start with the task in front of you. Every guide explains the normal path, the proof LiveHQ collects, and the recovery action when something is not ready.
Operate
- Install secure LiveHQ updatesUnderstand automatic discovery, signed installation, operation fencing, and the messages shown when a feed is unavailable.5 min
- Use the signed CLI and coding agentsGive a local coding agent a narrow deployment surface without giving it Docker or Keychain authority.10 min
- Diagnose common problemsUse the message LiveHQ already gives you, retry only safe boundaries, and collect bounded diagnostics when needed.8 min
The authority path
Convenient outside. Authority on your Mac.
The app expresses intent. The signed runtime agent alone operates Docker Desktop, runtime credentials, databases, and the outbound tunnel.
- 01LiveHQ app or signed CLI
- 02Signed typed-XPC runtime agent
- 03Docker Desktop and local databases
- 04Outbound OriginLink tunnel
- 05Managed public HTTPS
