> Rally Help Center. Index of every page: https://rallywith.ai/help/llms.txt
> This chapter's pages: https://rallywith.ai/help/working-with-rally/llms.txt

# Code, data and the Terminal

> Rally has its own private Linux computer for running code, crunching data and working on GitHub repositories.

Some questions are best answered by a calculator, not a conversation. "What is
the average deal size by region in this spreadsheet?" has one right answer,
and the reliable way to get it is to run the numbers. So Rally has a computer
of its own to do that on. Rally calls it the **Terminal**.

## Rally's own computer

The Terminal is a small Linux computer that Rally borrows while it works. It
is a **sandbox**, which means it is sealed off: it is not your Mac, it cannot
see your files unless you give them to Rally, and nothing Rally does in it can
touch your own computer. It is a workshop out the back, where Rally can make a
mess and bring you the finished piece.

On it, Rally can write and run programs in Python, JavaScript, TypeScript and
shell scripts, and use a SQLite database. It can install extra tools when it
needs them. In practice that means it can:

- Do maths properly, rather than in its head.
- Clean up, reshape, merge and convert data files.
- Analyse a spreadsheet, a log file or a pile of CSVs.
- Make charts, datasets, reports, images and zip archives.
- Build documents and small web sites
  (see [Live sites](https://rallywith.ai/help/things-rally-makes/live-sites.md)).

You do not need to know any of those languages. Ask for the result and Rally
picks the tool.

## Using it

Ask for what you want:

- "Here is our sales export. Which five customers grew fastest this year? Make
  a bar chart."
- "Convert these three CSVs into one Excel file with a tab each."
- "How many working days are there between now and the launch on 3 March?"
- "Find the duplicate rows in this list and give me a cleaned copy."

Rally loads its **Terminal** plugin and gets to work. Its activity is grouped
under **Computer** in the conversation, with rows such as **Running a
command**, **Writing a file** and **Copying an attachment into the sandbox**
(that last one is Rally taking a file you attached and putting it on its
computer so it can work on it).

When Rally makes something you will want, such as a chart, a cleaned-up file
or a report, it brings it back into the Channel as a file. If it makes the same
file again later, you get a new version of that file rather than a second copy.
Files are covered in [Artifacts](https://rallywith.ai/help/things-rally-makes/artifacts.md).

## One computer per conversation

Each conversation gets its own sandbox. The Channel has one, each Breakout has
its own, and each Sidekick run has its own. Helpers that Rally starts from a
conversation share that conversation's sandbox (helpers come up in
[Helpers, other conversations and receipts](https://rallywith.ai/help/working-with-rally/helpers-and-receipts.md)).

The sandbox is not kept running all the time. After about five minutes with
nothing to do it goes to sleep, and Rally wakes it up the next time it needs
it. Files Rally left on it come back. Anything that was still running, such as
a test web server, does not.

> [!WARNING]
> The sandbox is a workshop, not a filing cabinet. It is deleted after 30 days.
> Anything worth keeping should come back into the Channel as a file, so ask
> Rally to "save that into the Channel" if it has not already.

## What it cannot do

The sandbox is a modest machine with a fixed size:

- **Big jobs can run out of room.** It has 2 processors, 4 GB of memory and
  8 GB of disk. A job that needs more stops partway, and Rally tells you it
  failed.
- **One command runs at most 15 minutes.** A long calculation has to be
  split up.
- **Nothing interactive.** Rally cannot run a program that sits waiting for
  someone to type, or leave a server running in the background.
- **Huge outputs are cut off.** A command that prints a vast amount of text
  fails with an output limit.

### Where it may connect on the internet

Code in the sandbox can reach the internet, but only as far as your
Organization allows. An administrator chooses between two settings in
**Settings → Internet access**, under **Terminal network access**:

- **Trusted only**: the services Rally needs to work, plus any extra
  addresses the Organization approves.
- **Full internet**: any public address.

Either way, the sandbox cannot reach private networks. If Rally says a
download was blocked, this setting is usually why. Ask an administrator, and
see [Organization settings](https://rallywith.ai/help/running-an-organization/organization-settings.md).

### When the Terminal is unavailable

The Terminal is not switched on in every region, and the Rally team can pause
it for safety. When it is unavailable, Rally's code tools fail with a message
saying the sandbox is unavailable, and **Settings → Internet access** shows
**Terminal unavailable**. Rally then answers in the
conversation as best it can without running code.

## Working on GitHub repositories

If you have connected GitHub, Rally can work on your code the way a developer
would. Give it a bug or a small change and get a pull request back to review.

Ask something like:

- "In `acme/website`, the footer year is hard-coded. Fix it and open a PR."
- "Run the tests in `acme/billing` and tell me what is failing."
- "Look at the open PR for the login page and address the review comments."

Rally picks the exact repository from the ones you have given it access to,
copies it onto its sandbox (**Checking out a repository**), reads and edits the
code, runs tests, commits its changes, and opens or updates a pull request
(**Opening a pull request**). If the repository has its own instruction files
for AI agents (files called `AGENTS.md`), Rally reads and follows them.

Some ground rules Rally keeps to:

- **It asks for the least access it needs.** For reading and testing, it uses
  read-only access. It can still edit and commit on its sandbox, but it cannot
  push anything to GitHub. It asks for write access only when the job is to
  push.
- **It works on one branch per Channel.** It pushes only that branch, never
  your main branch.
- **It does not touch your automated build setup.** Rally cannot change files
  in the repository's `.github/workflows` folder.
- **Closed is closed.** Rally does not reopen a pull request that was closed
  or merged.
- **Your word wins.** Instructions in a repository's `AGENTS.md` never give
  Rally extra permissions, and they lose to your instructions and Rally's own
  rules.

Which repositories Rally may touch is controlled from the GitHub connection.
See [GitHub](https://rallywith.ai/help/connecting-your-tools/github.md).

> [!TIP]
> Treat Rally's pull request like one from a new colleague: read the diff and
> let your tests run before you merge. It is good, but it is not the one who
> gets paged at 3 a.m.

Next: [Pictures and voices](https://rallywith.ai/help/working-with-rally/pictures-and-voices.md).
