{"schemaVersion":"developer.reits.tech/runner-credential-boundary/v1","status":"T01_REPOSITORY_IMPLEMENTED_LIVE_QUALIFICATION_REQUIRED","evaluatedAt":"2026-07-24T16:10:00Z","program":{"acceptedKnives":4,"totalKnives":36,"currentOrdinal":5,"currentKnife":"D05","remainingIncludingCurrent":32,"remainingAfterCurrentAcceptance":31},"task":{"id":"D05-T01","title":"Runner credential and task isolation firebreak","repositoryImplementationComplete":true,"liveQualified":false,"productionAccepted":false,"nextTask":"D05-T02","nextTaskTitle":"Restore an independent AWS validation identity"},"topology":{"organization":"reits","linuxRunners":2,"availabilityZones":2,"vpc":"dedicated-ci-only","ingressRules":0,"concurrencyPerRunner":1,"runnerMode":"ephemeral-single-job","taskMode":"docker-container","replacementMode":"power-off-then-asg-replace"},"controls":[{"id":"CRED-01","title":"Ephemeral runner credential","state":"REPOSITORY_BOUND","mechanism":"register --ephemeral; Gitea revokes the exposed runner credential before untrusted code starts"},{"id":"TASK-01","title":"Task container boundary","state":"REPOSITORY_BOUND","mechanism":"digest-pinned docker:// labels, privileged=false, valid_volumes=[], docker_host=\"-\" and no host socket mount"},{"id":"CLOUD-01","title":"Zero cloud authority at execution","state":"REPOSITORY_BOUND","mechanism":"IMDS disabled and instance profile detached before the daemon starts"},{"id":"NET-01","title":"Proxy-only task egress","state":"REPOSITORY_BOUND","mechanism":"reits-ci0 may reach only 172.30.0.1:3128; task DNS points to empty container loopback; Docker image pulls use loopback Squid; other host and forwarded sockets are rejected"},{"id":"LIFE-01","title":"Whole-machine retirement","state":"REPOSITORY_BOUND","mechanism":"daemon exits after one job; credential and task roots are wiped; VM powers off; ASG replaces it"}],"lifecycle":[{"ordinal":1,"state":"BOOTSTRAP","detail":"New encrypted Ubuntu VM starts in the isolated CI VPC with a temporary bootstrap profile."},{"ordinal":2,"state":"REGISTER","detail":"Root retrieves the SSM registration token and creates one ephemeral organization runner credential while the daemon is offline."},{"ordinal":3,"state":"QUARANTINE","detail":"The node disables IMDS, detaches its profile, signals CloudFormation, erases temporary AWS values and writes the activation marker."},{"ordinal":4,"state":"EXECUTE","detail":"The unprivileged daemon accepts one job; untrusted steps execute in a bounded Docker container without the host socket or runner credential."},{"ordinal":5,"state":"EGRESS","detail":"Task traffic is forced through the dedicated bridge to the root-managed CONNECT allowlist; private and direct destinations are denied."},{"ordinal":6,"state":"RETIRE","detail":"After the one job or any daemon failure, the host deletes containers, workspace, temp data and .runner, then powers off for ASG replacement."}],"repositoryEvidence":{"template":"ops/gitea-runner/cloudformation.yaml","deploy":"ops/gitea-runner/deploy.sh","liveVerifier":"ops/gitea-runner/finalize.sh","service":"ops/gitea-runner/reits-gitea-runner.service","egressGuard":"ops/gitea-runner/install-egress-guard.sh","retirement":"ops/gitea-runner/retire-instance.sh","preflight":"ops/gitea-runner/preflight.mjs","staticVerification":"npm run runner-credential-boundary:verify"},"liveEvidence":{"stackStatus":"NOT_DEPLOYED","organizationRunnersOnline":0,"adversarialJobsExecuted":0,"credentialReadAttemptsDenied":0,"metadataAttemptsDenied":0,"productionNetworkAttemptsDenied":0,"retirementReceiptsObserved":0,"replacementReceiptsObserved":0,"gateG01Satisfied":false},"invariants":{"paidResourcesCreated":0,"productionChangesAuthorized":0,"organizationRunnerCredentialInRepository":false,"hostDockerSocketMountedIntoTask":false,"taskCanReadRunnerCredential":false,"taskCanReachImds":false,"runnerReusableAcrossJobs":false,"d05Accepted":false,"programAdvanced":false},"officialReference":"https://docs.gitea.com/usage/actions/act-runner#ephemeral-runners","boundary":"Repository implementation is complete for D05-T01, but no paid cloud resource was created and no live adversarial receipt exists. This artifact does not satisfy G01 or accept D05."}