Architecture

Three small parts, one secure mesh.

The CLI talks to the server, the server dispatches to runners, and every hop is mutually authenticated.

Contigra CLI

  • Pipeline management
  • Health checks
  • Tutorials

Contigra Server

  • Job queue
  • Runner registry
  • mTLS security

Contigra Runner

  • Job execution
  • Health reporting
  • Container sandbox

Storage & observability

Artifact management, metrics and logs, and backup.

Security model

Trust nothing by default.

Zero-trust network

All communication is carried over mTLS.

Container isolation

Sandboxed execution with minimal privileges.

Audit trail

Security events are logged for review.

Request path

What happens when you run a pipeline.

  1. Resolve. The CLI parses contigra.toml and builds the dependency graph.
  2. Submit. In distributed mode, the job is sent to the server over mTLS-secured gRPC.
  3. Queue. The server queues the job and picks a healthy runner whose tags match.
  4. Execute. The runner executes each task in a sandboxed container and streams status back.
  5. Record. Results, logs, and metrics are stored and available for review.