writeonce/docs/guides
shoney.arickathil 3dcadefbfd docs(releasing): why the release job stays on a hosted runner
- self-hosted works technically: outbound HTTPS only, no inbound
  ports, honours HTTPS_PROXY/NO_PROXY — a box behind a proxy is fine
- but it defeats the pinned-runner decision: the build host sets the
  glibc floor, so a workstation runner (2.39 here) puts it back to
  2.38+ and drops Ubuntu 22.04 / Debian 12 / RHEL 9
- and a workstation-built release is unattested
- records what self-hosting accepts: jobs run as the starting user,
  with that user's ~/.ssh, credentials and network reach — including
  hosts named in ~/.ssh/config; worst on public repos, where a
  stranger's PR runs code on the runner
- if unavoidable: dedicated VM, unprivileged user, --ephemeral,
  segmented network, treat .credentials as a secret

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-25 05:16:43 +02:00
..
database-developer-subagent.md docs: postgres study — constraints/grammar + indexing cards; subagent guide 2026-08-22 16:13:48 +02:00
language-surface.md feat(lang+wo-html): raw text literals, component layer, MVC samples 2026-08-25 03:58:41 +02:00
releasing.md docs(releasing): why the release job stays on a hosted runner 2026-08-25 05:16:43 +02:00