RootPilot Edge
The boundary has exactly one opening, and it points outward: the runner dials the control-plane, never the other way around. Credentials don’t cross. Results do, already redacted.
Where to start
Section titled “Where to start”Quickstart
Bring up the whole catalog with a planted incident, without a single cloud credential.
ConceptOverview
What runs on which side of the boundary, and why the split is drawn where it is.
ProductionInstall for real
Pull the image, mount your tenant certificate, and run against the production tunnel.
ReferenceEnvironment variables
All 40 RUNNER_* settings, with defaults and what each one breaks.
Connector credentials
Which keys each of the 15 connectors asks for, and which are actually required.
PostureSecurity model
Read-only by construction, the 5 write exceptions, and the human gate covering them.
Agent surfaceConnect an agent
The address, the bearer and the session limits — the path the product is actually used through.
What the Agent does not do
Section titled “What the Agent does not do”The diagnostic intelligence — multi-source correlation, learning aggregation, decision thresholds — lives in the control-plane, on our side of the boundary. The Agent on its own is an executor of read calls.
The guarantee does not rest on taking our word for it: it is structural. Credentials are read from your secret manager and held only in memory, calls are read-only (with 5 write exceptions in Jira and Slack, each behind an explicit human confirmation), and PII redaction happens before any result crosses the boundary. The network path is outbound and originates with you — stop the container and no route into your infrastructure exists.