writeonce/docs
shoney.arickathil 3dcadefbfd docs(releasing): why the release job stays on a hosted runner
- self-hosted works technically: outbound HTTPS only, no inbound
  ports, honours HTTPS_PROXY/NO_PROXY — a box behind a proxy is fine
- but it defeats the pinned-runner decision: the build host sets the
  glibc floor, so a workstation runner (2.39 here) puts it back to
  2.38+ and drops Ubuntu 22.04 / Debian 12 / RHEL 9
- and a workstation-built release is unattested
- records what self-hosting accepts: jobs run as the starting user,
  with that user's ~/.ssh, credentials and network reach — including
  hosts named in ~/.ssh/config; worst on public repos, where a
  stranger's PR runs code on the runner
- if unavoidable: dedicated VM, unprivileged user, --ephemeral,
  segmented network, treat .credentials as a secret

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-25 05:16:43 +02:00
..
examples feat(serve+view): file serving, downloads, supported systems; rename 2026-08-25 04:41:00 +02:00
guides docs(releasing): why the release job stays on a hosted runner 2026-08-25 05:16:43 +02:00
in-progress docs: slice marker — T1/T2/T3/T6/T7 landed, T4/T5/T8/T9/T10 pending 2026-08-23 06:27:31 +02:00
plan feat(serve+view): file serving, downloads, supported systems; rename 2026-08-25 04:41:00 +02:00
stories feat(serve+view): file serving, downloads, supported systems; rename 2026-08-25 04:41:00 +02:00
superpowers feat: iteration 35 — net seams + the serving slice (fiber-per-connection) 2026-08-23 08:04:32 +02:00
00-code-review.md feat(serve+view): file serving, downloads, supported systems; rename 2026-08-25 04:41:00 +02:00
00-dependency-graph.md feat: iteration 35 — net seams + the serving slice (fiber-per-connection) 2026-08-23 08:04:32 +02:00
00-link-audit.md feat: iterations 19 + 17 — Float/Bytes scalars (.wob v5), library kind + internal/ 2026-08-20 19:24:15 +02:00
00-principles.md docs: principles — repoint 4 dead Rust-era links 2026-08-21 06:02:25 +02:00
01-problem.md docs: remove stale old-runtime docs; abandon the ##ui frontend track 2026-08-17 20:06:36 +02:00
08-project-structure.md docs: status board moved to docs/stories/00-status.md 2026-08-21 10:07:20 +02:00