RUNES
Pipelines generated from your own rules.
RUNES generates your continuous integration workflows from a conventions file and your security rules. You describe the rule once; RUNES applies it to every repository.
Where RUNES stands
RUNES isn't published yet, and we can't give you a demo today. The continuous integration part will be free and open source; the continuous deployment part relies on our infrastructure controller. Write to us to be notified when it's published.
A convention that isn't enforced isn't a convention.
Security rules written in a document get applied unevenly from one repository to the next. Generating the pipeline instead of documenting it removes the gap between the rule and its enforcement.
What RUNES does
5 capacités
-
Every major forge
GitHub, GitLab, Forgejo, and Gitea. Forgejo and Gitea aren't a footnote: they're the forges run by organizations that care about hosting their own code, and it's on one of them that we host ours.
-
One rule, one YAML file
Shared conventions (naming, expected artifacts) live in a global repository. Each repository carries only its own values: the artifacts its continuous integration produces, and the deployment targets to create, virtual machine, LXC container, or application container.
-
Security rules by default
Pinned action versions, SBOM generation, secret scanning, container image analysis, artifact signing. These are the generated pipeline's default settings, not an option left to each repository's discipline.
-
Forty repositories don't switch over at once
You migrate repository by repository, at your own pace, and a dry-run mode shows what would be written before anything actually is. Hand-written workflows stay in place until they've been migrated.
-
When the convention changes
A change to the global repository propagates to the repositories that inherit from it; whatever is specific to a repository changes there. Regeneration goes through a pull request: your maintainers review it and decide, following your own process.
The rule, in one file
Shared conventions live in a global repository. Each repository carries only what's specific to it: the artifacts its continuous integration produces, and the targets its deployment must create.
# runes.yaml
extends: pagma/conventions@v1
ci:
artifacts:
- name: api
type: container
registry: registry.example.fr/api
cd:
targets:
- kind: vm
host: proxmox-prod
- kind: lxc
host: proxmox-prod
- kind: container
runtime: podman
Illustrative example. The format isn't stabilized yet; this page will be updated once the format is published.
With your infrastructure
Connected to the infrastructure we operate, RUNES doesn't stop at continuous integration: the generated pipelines ask the controller to create the target machines and containers.
Let's talk about your pipelines.
Which forges do you use, and which rules do you want applied across all your repositories? Write to us: we'll notify you at launch, and your case will help shape what we build.
Technical detail
- Rule format
- YAML. One global repository for shared conventions, one file per repository for its own values.
- Forges
- GitHub, GitLab, Forgejo, Gitea, and other git forges.
- Generation
- Multi-platform pipelines generated from a single set of conventions.
- Default settings
- Pinned actions, SBOM, secret scanning, container image analysis, signed artifacts.
- Execution
- VS Code extension and command-line interface. Continuous deployment is run by the RUNES runner.
- License
- Continuous integration is free and open source; continuous deployment is included in the infrastructure service.
Pricing terms
- RUNES CI
- Free and open source.
- RUNES CD
- Included in the infrastructure service.
- Repositories
- Unlimited.