01 · The problem
Make the workflow clear.
Build execution and environment deployment need distinct ownership. A CI runner with broad cluster permissions makes that boundary difficult to review and recover.
02 · The approach
Give each part a job.
Source events create build resources in Kubernetes. Controllers reconcile isolated runner Jobs, which produce image evidence. A deployment repository records the release intent, and Argo CD or Flux reconciles the environment.
- Source event
- BuildRun resource
- Runner Job
- Image + GitOps commit
- Argo CD / Flux
03 · A practical starting point
Try the documented workflow.
./hack/kind-create.sh
./hack/kind-load-images.sh
./hack/install-dev.shRepository quickstart commands create a local kind environment. Docker, kind, kubectl, Helm, Go, and Node are prerequisites.
04 · The result
Something you can inspect.
The project documents a kind quickstart, an operations UI, and a credential-free example. Its published alpha has explicit readiness gates; development authentication settings require review before evaluating a production installation.

Based on the repository README, quickstart, and documented alpha readiness scope. Source and current status ↗