Menu
AkurAI-Build
publicfa36542
AkurAI Build
A small Git-native CI/CD system built with pinned Rust 1.97: one Rust binary for repositories, pipelines, Docker/native jobs, configurable Titan build workers, build matrices, logs, artifacts, protected deployments, webhooks, filterable CLI/API queries, and a responsive MiniJinja workbench.
It keeps the useful center of Jenkins, GitLab CI, GoCD, Concourse, and Woodpecker with a minimal authenticated Smart HTTP Git host, but without plugin markets, cluster control planes, or frontend frameworks.
Foundation
AkurAI Build starts from Bunfork's proven shape:
- Rust single binary
- encrypted SQLCipher state and ordered migrations
- bounded Axum/Hyper HTTP serving
- MiniJinja templates and dependency-free Ponytail UI
- strict CSP, constant-time tokens, protected files, and hardened systemd
- digest-recorded artifacts and rollback-oriented deployment
Bunfork remains a supported artifact target; AkurAI Build replaces its unrelated vector/demo application surface with CI/CD.
Production topology
https://akurai-build.olibuijr.com
│ TLS
▼
EC2 Nginx / AkurAI-VPN
│ private 100.88.0.0/16
▼
Titan 100.88.0.9:3210
├── akurai-build-service (HTTP, AKURAI_WORKERS=0)
├── akurai-build-worker (execution, AKURAI_WORKERS=1)
├── Docker / BuildKit
├── encrypted SQLite
└── workspaces, cache, artifacts
All releases use the MCP-controlled immutable pipeline:
local commit → repo_sync → run_queue(exact SHA) → promote production → persisted success
The protected self-pipeline consumes the package artifact, replaces only the service container, verifies both service and worker health, and rolls back the service automatically if health fails. Worker-image and host MCP maintenance remain explicit out-of-band operations so a running worker never self-severs.
Pipeline
Commit .akurai.yml:
version: 1
jobs:
- name: test
image: oven/bun:1.3
network: true
run:
- bun install --frozen-lockfile
- bun test
matrix:
platform: [linux/amd64, linux/arm64]
cache: [.bun]
- name: package
needs: [test]
image: oven/bun:1.3
run: bun build src/index.ts --compile --outfile dist/app
artifacts: [dist/**]
- name: deploy
needs: [package]
executor: native
environment: production
approval: true
branches: [main]
secrets: [DEPLOY_TOKEN]
run: akurai-ec2 release --mode publish --yes
Jobs default to depending on the previous job; set needs: [] for an independent root. Caches are isolated by registered repository and shared by its jobs. Matrix axes expand to at most 32 variants and become AKURAI_MATRIX_<AXIS> variables. platform also selects Docker's --platform.
Docker jobs run with dropped capabilities, no-new-privileges, fixed CPU/memory/PID limits, a read-only root, writable workspace/tmp, host UID/GID, and no network unless network: true. Linux amd64/arm64 variants use Titan Docker with pinned tonistiigi/binfmt:qemu-v10.2.3-68 QEMU registration, rechecked by every deploy. Native jobs are disabled unless the repository is trusted and AKURAI_ALLOW_NATIVE=1 is set.
Declared secrets resolve only from AKURAI_SECRET_<NAME>, are omitted from Docker arguments, and are exact-value-redacted from retained logs. Repository writers with secret-bearing jobs are privileged because build code can intentionally transform or exfiltrate a secret.
CLI for people and agents
Every query and mutation command emits one JSON envelope. mcp is the newline-delimited JSON-RPC stdio transport.
akurai-build doctor
akurai-build repo add app https://github.com/org/app.git --branch main
akurai-build repo host app /home/olafurbui/Projects/app --branch main
akurai-build repo sync app /home/olafurbui/Projects/app
akurai-build repo list --search app --visibility private
akurai-build run app --git-ref main
akurai-build runs --repo app,worker --status failed,interrupted --trigger manual,webhook --search compiler --limit 20
akurai-build show 42
akurai-build wait 42 --timeout 3600
akurai-build logs 42 --failed
akurai-build retry 42
akurai-build promote 42 production
akurai-build artifact get 7 ./artifact.bin
akurai-build workers
The bundled skills/akurai-build/SKILL.md makes these the stable operating surface for BunFast and OMP agents. repo host creates a bare mirror below the protected AkurAI Build data root and atomically switches the CI registration to it; repo sync refreshes that mirror from its trusted Titan checkout. repo list filters by text and visibility. runs accepts comma-separated --repo, --status, and --trigger filters plus exact --git-ref, free-text --search, bounded --limit, and --offset; /api/state exposes the same run query shape. Agents must verify persisted succeeded states rather than infer success from process output.
MCP query server
akurai mcp serves four read-only MCP tools over stdio: akurai_repositories, akurai_runs, akurai_run, and akurai_workers. Repository and run tools accept the same composable filters as the CLI, including a string, comma-separated string, or array for multi-value run filters. Configure an MCP client to launch the maintained entrypoint:
{
"mcpServers": {
"akurai-build": {
"command": "akurai-build",
"args": ["cli", "mcp"]
}
}
}
Hosted Git
Hosted repositories are available at https://akurai-build.olibuijr.com/git/<name>.git. Smart HTTP reads and writes require the existing AkurAI Build bearer token; the token must be supplied through a protected credential helper or maintained command, never a URL, command argument, source file, or log. CI uses the local bare mirror directly, so builds do not depend on public DNS or the edge proxy.
Git webhooks
Use:
POST https://akurai-builds.olibuijr.com/api/hooks/<repository-name>
Supported authentication:
- GitHub
X-Hub-Signature-256 - Gitea
X-Gitea-Signature - GitLab
X-Gitlab-Token
The secret is the protected webhook.token; do not expose it in commands or documentation. Push payloads supply ref and the immutable commit. Manual/UI/API mutations require the separate bearer API token.
State and recovery
- A run stores its resolved immutable commit before reading
.akurai.yml. - Jobs execute fail-fast in dependency order; all variants of a dependency must succeed.
- Artifacts are bounded, SHA-256 recorded, copied without symlinks/traversal, and served only after authorization.
- A protected deployment records the exact upstream artifact IDs and digests before execution.
- Every Titan worker persists its status, capacity, heartbeat, current run, and completed-run count; restart recovery marks stale workers offline before registering the configured pool.
- systemd restarts controller failures;
akurai-ec2 release --mode rollbackrestores the prior binary.
Run evidence is the system's operational knowledge. It supports debugging and safe iteration without allowing unreviewed self-modifying code.
Limits kept intentionally
The first release uses one Titan scheduler with a configurable local worker pool and SQLite. Each worker owns one run at a time; jobs inside a run remain dependency-ordered and isolated. Linux container matrices are complete; native Windows/macOS and remote Windows-container builds wait for a signed artifact-streaming agent protocol rather than pretending remote bind mounts are portable. Object storage, provider commit-status adapters, and role-based multi-user accounts are deferred—not stubbed.
Development
akurai-ec2 release --mode publish --yes # deploy (check, build, publish, restart)
akurai-ec2 release runs formatting, Clippy with warnings denied, and all locked tests before publishing. Direct deployment or publication commands are outside the operating contract.