Chapter 4 · Working with the agent / 4.3
Code, data and the Terminal
Rally has its own private Linux computer for running code, crunching data and working on GitHub repositories.
Some questions are best answered by a calculator, not a conversation. "What is the average deal size by region in this spreadsheet?" has one right answer, and the reliable way to get it is to run the numbers. So Rally has a computer of its own to do that on. Rally calls it the Terminal.
Rally's own computer
The Terminal is a small Linux computer that Rally borrows while it works. It is a sandbox, which means it is sealed off: it is not your Mac, it cannot see your files unless you give them to Rally, and nothing Rally does in it can touch your own computer. It is a workshop out the back, where Rally can make a mess and bring you the finished piece.
On it, Rally can write and run programs in Python, JavaScript, TypeScript and shell scripts, and use a SQLite database. It can install extra tools when it needs them. In practice that means it can:
- Do maths properly, rather than in its head.
- Clean up, reshape, merge and convert data files.
- Analyse a spreadsheet, a log file or a pile of CSVs.
- Make charts, datasets, reports, images and zip archives.
- Build documents and small web sites (see Live sites).
You do not need to know any of those languages. Ask for the result and Rally picks the tool.
Using it
Ask for what you want:
- "Here is our sales export. Which five customers grew fastest this year? Make a bar chart."
- "Convert these three CSVs into one Excel file with a tab each."
- "How many working days are there between now and the launch on 3 March?"
- "Find the duplicate rows in this list and give me a cleaned copy."
Rally loads its Terminal plugin and gets to work. Its activity is grouped under Computer in the conversation, with rows such as Running a command, Writing a file and Copying an attachment into the sandbox (that last one is Rally taking a file you attached and putting it on its computer so it can work on it).
When Rally makes something you will want, such as a chart, a cleaned-up file or a report, it brings it back into the Channel as a file. If it makes the same file again later, you get a new version of that file rather than a second copy. Files are covered in Artifacts.
One computer per conversation
Each conversation gets its own sandbox. The Channel has one, each Breakout has its own, and each Sidekick run has its own. Helpers that Rally starts from a conversation share that conversation's sandbox (helpers come up in Helpers, other conversations and receipts).
The sandbox is not kept running all the time. After about five minutes with nothing to do it goes to sleep, and Rally wakes it up the next time it needs it. Files Rally left on it come back. Anything that was still running, such as a test web server, does not.
Warning
The sandbox is a workshop, not a filing cabinet. It is deleted after 30 days. Anything worth keeping should come back into the Channel as a file, so ask Rally to "save that into the Channel" if it has not already.
What it cannot do
The sandbox is a modest machine with a fixed size:
- Big jobs can run out of room. It has 2 processors, 4 GB of memory and 8 GB of disk. A job that needs more stops partway, and Rally tells you it failed.
- One command runs at most 15 minutes. A long calculation has to be split up.
- Nothing interactive. Rally cannot run a program that sits waiting for someone to type, or leave a server running in the background.
- Huge outputs are cut off. A command that prints a vast amount of text fails with an output limit.
Where it may connect on the internet
Code in the sandbox can reach the internet, but only as far as your Organization allows. An administrator chooses between two settings in Settings → Internet access, under Terminal network access:
- Trusted only: the services Rally needs to work, plus any extra addresses the Organization approves.
- Full internet: any public address.
Either way, the sandbox cannot reach private networks. If Rally says a download was blocked, this setting is usually why. Ask an administrator, and see Organization settings.
When the Terminal is unavailable
The Terminal is not switched on in every region, and the Rally team can pause it for safety. When it is unavailable, Rally's code tools fail with a message saying the sandbox is unavailable, and Settings → Internet access shows Terminal unavailable. Rally then answers in the conversation as best it can without running code.
Working on GitHub repositories
If you have connected GitHub, Rally can work on your code the way a developer would. Give it a bug or a small change and get a pull request back to review.
Ask something like:
- "In
acme/website, the footer year is hard-coded. Fix it and open a PR." - "Run the tests in
acme/billingand tell me what is failing." - "Look at the open PR for the login page and address the review comments."
Rally picks the exact repository from the ones you have given it access to,
copies it onto its sandbox (Checking out a repository), reads and edits the
code, runs tests, commits its changes, and opens or updates a pull request
(Opening a pull request). If the repository has its own instruction files
for AI agents (files called AGENTS.md), Rally reads and follows them.
Some ground rules Rally keeps to:
- It asks for the least access it needs. For reading and testing, it uses read-only access. It can still edit and commit on its sandbox, but it cannot push anything to GitHub. It asks for write access only when the job is to push.
- It works on one branch per Channel. It pushes only that branch, never your main branch.
- It does not touch your automated build setup. Rally cannot change files
in the repository's
.github/workflowsfolder. - Closed is closed. Rally does not reopen a pull request that was closed or merged.
- Your word wins. Instructions in a repository's
AGENTS.mdnever give Rally extra permissions, and they lose to your instructions and Rally's own rules.
Which repositories Rally may touch is controlled from the GitHub connection. See GitHub.
Tip
Treat Rally's pull request like one from a new colleague: read the diff and let your tests run before you merge. It is good, but it is not the one who gets paged at 3 a.m.
Next: Pictures and voices.