RootPilot Edge
The boundary has exactly one opening, and it points outward: the runner dials the control-plane, never the other way around. Credentials don’t cross. Results do, already redacted.
Where to start
Section titled “Where to start”Quickstart
Bring up the whole catalog with a planted incident, without a single cloud credential.
ConceptOverview
What runs on which side of the boundary, and why the split is drawn where it is.
ProductionInstall for real
Enrollment, cloud-identity attestation, and the fleet against the production tunnel.
ReferenceEnvironment variables
All 40 RUNNER_* settings, with defaults and what each one breaks.
Connector credentials
Which keys each of the 15 connectors asks for, and which are actually required.
PostureSecurity model
Read-only by construction, the 5 write exceptions, and the human gate covering them.
What this repository does not contain
Section titled “What this repository does not contain”The diagnostic intelligence (multi-source correlation, learning aggregation, decision thresholds) lives in the control-plane, which is closed. The edge on its own is an auditable API executor, and that is the point: you don’t have to trust RootPilot to check exactly what touches your credentials.