Architecture
Three small parts, one secure mesh.
The CLI talks to the server, the server dispatches to runners, and every hop is mutually authenticated.
Contigra CLI
- Pipeline management
- Health checks
- Tutorials
Contigra Server
- Job queue
- Runner registry
- mTLS security
Contigra Runner
- Job execution
- Health reporting
- Container sandbox
Storage & observability
Artifact management, metrics and logs, and backup.
Security model
Trust nothing by default.
Zero-trust network
All communication is carried over mTLS.
Container isolation
Sandboxed execution with minimal privileges.
Audit trail
Security events are logged for review.
Request path
What happens when you run a pipeline.
- Resolve. The CLI parses
contigra.tomland builds the dependency graph. - Submit. In distributed mode, the job is sent to the server over mTLS-secured gRPC.
- Queue. The server queues the job and picks a healthy runner whose tags match.
- Execute. The runner executes each task in a sandboxed container and streams status back.
- Record. Results, logs, and metrics are stored and available for review.