RUNES

Pipelines generated from your own rules.

RUNES generates your continuous integration workflows from a conventions file and your security rules. You describe the rule once; RUNES applies it to every repository.

Where RUNES stands

RUNES isn't published yet, and we can't give you a demo today. The continuous integration part will be free and open source; the continuous deployment part relies on our infrastructure controller. Write to us to be notified when it's published.

A convention that isn't enforced isn't a convention.

Security rules written in a document get applied unevenly from one repository to the next. Generating the pipeline instead of documenting it removes the gap between the rule and its enforcement.

RUNES pipeline generationA repository and a rule set (conventions and security) produce a generated workflow, pushed to the forge. An optional return path triggers continuous deployment on your infrastructure.Repositorylanguage, target, contextConventionswritten onceRUNESgenerates the workflow foreach platformSecurity rulesapplied by defaultGenerated workflowcontinuous integrationGitHub · GitLab ·Forgejo · GiteaoptionalInfrastructurecontinuous deployment

What RUNES does

5 capacités

  1. Every major forge

    GitHub, GitLab, Forgejo, and Gitea. Forgejo and Gitea aren't a footnote: they're the forges run by organizations that care about hosting their own code, and it's on one of them that we host ours.

  2. One rule, one YAML file

    Shared conventions (naming, expected artifacts) live in a global repository. Each repository carries only its own values: the artifacts its continuous integration produces, and the deployment targets to create, virtual machine, LXC container, or application container.

  3. Security rules by default

    Pinned action versions, SBOM generation, secret scanning, container image analysis, artifact signing. These are the generated pipeline's default settings, not an option left to each repository's discipline.

  4. Forty repositories don't switch over at once

    You migrate repository by repository, at your own pace, and a dry-run mode shows what would be written before anything actually is. Hand-written workflows stay in place until they've been migrated.

  5. When the convention changes

    A change to the global repository propagates to the repositories that inherit from it; whatever is specific to a repository changes there. Regeneration goes through a pull request: your maintainers review it and decide, following your own process.

The rule, in one file

Shared conventions live in a global repository. Each repository carries only what's specific to it: the artifacts its continuous integration produces, and the targets its deployment must create.

# runes.yaml
extends: pagma/conventions@v1

ci:
  artifacts:
    - name: api
      type: container
      registry: registry.example.fr/api

cd:
  targets:
    - kind: vm
      host: proxmox-prod
    - kind: lxc
      host: proxmox-prod
    - kind: container
      runtime: podman

Illustrative example. The format isn't stabilized yet; this page will be updated once the format is published.

With your infrastructure

Connected to the infrastructure we operate, RUNES doesn't stop at continuous integration: the generated pipelines ask the controller to create the target machines and containers.

Let's talk about your pipelines.

Which forges do you use, and which rules do you want applied across all your repositories? Write to us: we'll notify you at launch, and your case will help shape what we build.

Technical detail

Rule format
YAML. One global repository for shared conventions, one file per repository for its own values.
Forges
GitHub, GitLab, Forgejo, Gitea, and other git forges.
Generation
Multi-platform pipelines generated from a single set of conventions.
Default settings
Pinned actions, SBOM, secret scanning, container image analysis, signed artifacts.
Execution
VS Code extension and command-line interface. Continuous deployment is run by the RUNES runner.
License
Continuous integration is free and open source; continuous deployment is included in the infrastructure service.

Pricing terms

RUNES CI
Free and open source.
RUNES CD
Included in the infrastructure service.
Repositories
Unlimited.