Single-use V1 design
The V1 design plans to assign a fresh Firecracker microVM to each job and destroy the worker after completion, cancellation, or an interrupted run.
Security approach
Runzivo V1 is designed to run an approved GitHub Actions job in an ephemeral Firecracker microVM. The runner and its environment are single-use.
The V1 design plans to assign a fresh Firecracker microVM to each job and destroy the worker after completion, cancellation, or an interrupted run.
The V1 design requires GitHub App installation for selected repositories. Labels select a supported runner configuration but do not grant repository access.
The V1 design uses short-lived GitHub App installation and JIT runner credentials. Platform and control-plane credentials stay out of customer workers.
Before external workloads, V1 requires restrictive process isolation, resource limits, immutable runner images, and host-enforced network controls. Runzivo will name a specific host region here once it is committed to customers.
Planned per-job isolation
These are V1 design requirements. Runzivo will keep them marked Planned until required launch validation is complete.
Early Access boundary
Runzivo publishes compliance, service, and platform claims only after validation. Before accepting external workloads, Runzivo tests lifecycle, isolation, network egress, image integrity, patching, and teardown.
For a security report, contact security@runzivo.dev.