Skip to content

docs(runners): document private image runner deployment - #32

Merged
jmgilman merged 1 commit into
masterfrom
docs/private-image-runners
Sep 13, 2026
Merged

jmgilman merged 1 commit into
masterfrom
docs/private-image-runners

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Change

  • Add the centralized private-runner deployment and qualification runbook, navigation, and controller/runner network reservations.
  • Document separate App and Incus identities, systemd credential delivery, protected dispatch and public-master ancestry gates, GHCR package grants, and shared-host/validator residuals.
  • Document the real v2.0.0 attested DEB bootstrap and pinned digest because the upstream apt example does not publish the package.
  • State explicitly that the private bake does not mint the retired hosted workflow artifact attestations.
  • No design documents changed.

Verification

moon run docs:build passed. The documented controller deployment, private-only standby registration, proxy allow/deny checks, ancestry rejection and no-op OpenTofu plan were exercised. Full image publication qualification is in progress.

Companions: GilmanLab/agentcompute#17, GilmanLab/agentcompute-images#1, GilmanLab/fleet#17, GilmanLab/fleet#18, GilmanLab/secrets#37; upstream meigma/incus-gh-runner#69. Leave this PR unmerged.

@jmgilman
jmgilman merged commit d6833e1 into master Sep 13, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant