AkurAI Build
Menu

AkurAI-Build

public
b3b852c9e5e5f260c70f0d221da171b4b5083845 116 commits 27 branches 10 tags
Ólafur Búi Ólafsson fix: install health manifest in pipeline b3b852c
.cargo Run controller with Docker group and pin CI toolchain .impeccable feat: add Ponytail UI design system app fix(public-ui): complete negotiated code errors deploy fix: install health manifest in pipeline docs Checkpoint WIP + rustfmt + AkurAI Build CI/CD pipeline migrations feat: add managed deployment provenance public fix(public-ui): complete negotiated code errors scripts Fix self-deployed host tool installation skills Document repository blob MCP contract src feat(worker): reconcile worker table to configured count on startup tests feat: add managed deployment provenance .akurai.yml fix: keep deployments in MCP pipelines 1512 .dockerignore Fix run deep links and bound deploy context (AKURAI-BUILD-5) 71 .gitignore Initial commit: bunfork v0.1.0 source tree 171 AGENTS.md mcp: never block the request loop on pipeline execution 828 akurai.example.yml Redesign public homepage and add social discovery 563 Cargo.lock release: v1.4.8 36094 Cargo.toml release: v1.4.8 1643 CHANGELOG.md release: v1.4.8 4213 CLAUDE.md Replace the JSON CI CLI with a full read/write akurai-build MCP tool set (repo add/host/sync/rename/remove/visibility/branches/tree, run queue/wait/retry/promote, artifact get, doctor, init); keep keygen/migrate/serve as plain CLI subcommands; update skill and deploy.md to the MCP tool set 11 deploy.md Repair Bun helper in live worker 5629 deploy.sh Harden repository MCP and Bun worker tools 17245 LICENSE Initial commit: bunfork v0.1.0 source tree 1077 README.md Harden repository MCP and Bun worker tools 8488 rust-toolchain.toml Pin actual Rust 1.97 build toolchain 87 THIRD_PARTY_NOTICES.md docs: refresh stale dependency, MSRV, and test-count references 3346
README.md

AkurAI Build

A small Git-native CI/CD system built with pinned Rust 1.97: one Rust binary for repositories, pipelines, Docker/native jobs, configurable Titan build workers, build matrices, logs, artifacts, protected deployments, webhooks, filterable CLI/API queries, and a responsive MiniJinja workbench.

It keeps the useful center of Jenkins, GitLab CI, GoCD, Concourse, and Woodpecker with a minimal authenticated Smart HTTP Git host, but without plugin markets, cluster control planes, or frontend frameworks.

Foundation

AkurAI Build starts from Bunfork's proven shape:

  • Rust single binary
  • encrypted SQLCipher state and ordered migrations
  • bounded Axum/Hyper HTTP serving
  • MiniJinja templates and dependency-free Ponytail UI
  • strict CSP, constant-time tokens, protected files, and hardened systemd
  • digest-recorded artifacts and rollback-oriented deployment

Bunfork remains a supported artifact target; AkurAI Build replaces its unrelated vector/demo application surface with CI/CD.

Production topology

https://akurai-build.olibuijr.com
        │ TLS
        ▼
EC2 Nginx / AkurAI-VPN
        │ private 100.88.0.0/16
        ▼
Titan 100.88.0.9:3210
  ├── akurai-build-service (HTTP, AKURAI_WORKERS=0)
  ├── akurai-build-worker (execution, AKURAI_WORKERS=1)
  ├── Docker / BuildKit
  ├── encrypted SQLite
  └── workspaces, cache, artifacts

All releases use the MCP-controlled immutable pipeline:

local commit → repo_sync → run_queue(exact SHA) → promote production → persisted success

The protected self-pipeline consumes the package artifact, replaces only the service container, verifies service and worker health, then atomically installs the packaged stdio MCP binary and shared CI helpers. Any failed step rolls the service back. Worker-image replacement remains a separate host-maintenance operation so a running worker never replaces itself.

Pipeline

Commit .akurai.yml:

version: 1
jobs:
  - name: test
    image: oven/bun:1.3
    network: true
    run:
      - bun install --frozen-lockfile
      - bun test
    matrix:
      platform: [linux/amd64, linux/arm64]
    cache: [.bun]

  - name: package
    needs: [test]
    image: oven/bun:1.3
    run: bun build src/index.ts --compile --outfile dist/app
    artifacts: [dist/**]

  - name: deploy
    needs: [package]
    executor: native
    environment: production
    approval: true
    branches: [main]
    secrets: [DEPLOY_TOKEN]
    run: akurai-ec2 release --mode publish --yes

Jobs default to depending on the previous job; set needs: [] for an independent root. Caches are isolated by registered repository and shared by its jobs. Matrix axes expand to at most 32 variants and become AKURAI_MATRIX_<AXIS> variables. platform also selects Docker's --platform.

Docker jobs run with dropped capabilities, no-new-privileges, fixed CPU/memory/PID limits, a read-only root, writable workspace/tmp, host UID/GID, and no network unless network: true. Linux amd64/arm64 variants use Titan Docker with pinned tonistiigi/binfmt:qemu-v10.2.3-68 QEMU registration, rechecked by every deploy. Native jobs are disabled unless the repository is trusted and AKURAI_ALLOW_NATIVE=1 is set.

Declared secrets resolve only from AKURAI_SECRET_<NAME>, are omitted from Docker arguments, and are exact-value-redacted from retained logs. Repository writers with secret-bearing jobs are privileged because build code can intentionally transform or exfiltrate a secret.

Operator CLI and agent MCP

Every CLI command emits one JSON envelope for operator use. Agents use the configured AkurAI Build MCP tools for repository, run, artifact, approval, and deployment state; they never substitute CLI or raw stdio calls.

akurai-build doctor
akurai-build repo add app https://github.com/org/app.git --branch main
akurai-build repo host app /home/olafurbui/Projects/app --branch main
akurai-build repo sync app /home/olafurbui/Projects/app
akurai-build repo list --search app --visibility private
akurai-build run app --git-ref main
akurai-build runs --repo app,worker --status failed,interrupted --trigger manual,webhook --search compiler --limit 20
akurai-build show 42
akurai-build wait 42 --timeout 3600
akurai-build logs 42 --failed
akurai-build retry 42
akurai-build promote 42 production
akurai-build artifact get 7 ./artifact.bin
akurai-build workers

The CLI remains an operator and local-development surface. repo host creates a bare mirror below the protected AkurAI Build data root and atomically switches the CI registration to it; repo sync refreshes that mirror from its trusted Titan checkout. runs accepts composable repository, status, trigger, ref, and text filters. Agent publication and deployment use the matching configured MCP tools and require a persisted succeeded state.

MCP control plane

The configured akurai-build stdio server exposes the full MCP-controlled workflow:

  • repository registration, hosting, synchronization, visibility, branch heads, directory trees, and bounded file blobs;
  • immutable run queueing, querying, waiting, retrying, canceling, logs, and protected-environment promotion;
  • artifact retrieval, worker status, diagnostics, pipeline initialization, and semantic releases.

akurai_repo_branches returns the exact SHA for every branch head. akurai_repo_tree accepts a branch or immutable commit and a directory path; akurai_repo_blob reads a bounded UTF-8 file at a ref and path. The maintained launch entrypoint is deploy.sh mcp; clients use the configured mcp__akurai_build_* tools rather than invoking it directly.

Hosted Git

Hosted repositories are available at https://akurai-build.olibuijr.com/git/<name>.git. Smart HTTP reads and writes require the existing AkurAI Build bearer token; the token must be supplied through a protected credential helper or maintained command, never a URL, command argument, source file, or log. CI uses the local bare mirror directly, so builds do not depend on public DNS or the edge proxy.

Git webhooks

Use:

POST https://akurai-builds.olibuijr.com/api/hooks/<repository-name>

Supported authentication:

  • GitHub X-Hub-Signature-256
  • Gitea X-Gitea-Signature
  • GitLab X-Gitlab-Token

The secret is the protected webhook.token; do not expose it in commands or documentation. Push payloads supply ref and the immutable commit. Manual/UI/API mutations require the separate bearer API token.

State and recovery

  • A run stores its resolved immutable commit before reading .akurai.yml.
  • Jobs execute fail-fast in dependency order; all variants of a dependency must succeed.
  • Artifacts are bounded, SHA-256 recorded, copied without symlinks/traversal, and served only after authorization.
  • A protected deployment records the exact upstream artifact IDs and digests before execution.
  • Every Titan worker persists its status, capacity, heartbeat, current run, and completed-run count; restart recovery marks stale workers offline before registering the configured pool.
  • Compose restarts failed service/worker containers. The protected .akurai.yml deployment replaces only the service, verifies both health endpoints, installs the packaged MCP/host helpers, and rolls the service back on failure.

Run evidence is the system's operational knowledge. It supports debugging and safe iteration without allowing unreviewed self-modifying code.

Limits kept intentionally

The first release uses one Titan scheduler with a configurable local worker pool and SQLite. Each worker owns one run at a time; jobs inside a run remain dependency-ordered and isolated. Linux container matrices are complete; native Windows/macOS and remote Windows-container builds wait for a signed artifact-streaming agent protocol rather than pretending remote bind mounts are portable. Object storage, provider commit-status adapters, and role-based multi-user accounts are deferred—not stubbed.

Development and release

Run cargo fmt --all -- --check, Clippy with warnings denied, and cargo test --workspace locally. Commit only intended paths, publish with akurai_repo_sync, require the hosted branch SHA to match, then queue that exact commit. Production changes run only through the repository's approval-gated .akurai.yml; wait, promote explicitly, require persisted success, and verify the changed behavior.