Orkestia
Blog
DevKit

Local coding runner

Provider-blind DevKit runner — claim Staff coding assignments against local repos without giving the agent your git credentials

ltinteg-devkit runner is the trusted local broker for Staff coding work. It proves your API-token organization, registers against a cloudless devkit runner group, and claims opaque assignments. The coding child never receives a provider URL, a GitHub/GitLab id, a broker token, or a registry path.

This is the local side of Tickets & software delivery: the agent plans and edits; DevKit (the parent) is the only process that may talk to Git remotes, and only for exact-OID publication you already acknowledged.

Map a repository

repository_uuid is Orkestia's provider-neutral id — not owner/name.

ltinteg-devkit runner repositories add <repository-uuid> /absolute/path/to/repo \
  --allowed-root /absolute/root/containing/repos

ltinteg-devkit runner repositories list
ltinteg-devkit runner status

ltinteg-devkit runner serve --group <runner-group-uuid>

Allowed roots are mandatory (runner_allowed_roots or repeatable --allowed-root). Paths outside those roots are rejected. runner status redacts local paths.

What the child does not get

The broker launches the runtime (ltinteg-agent-runner by default) in the owned worktree with:

  • a run-scoped agent token
  • fixed Orkestia API URLs
  • opaque assignment ids

It does not inherit provider keys, broker credentials, SSH agents, credential helpers, or home paths. Git fetch/push from the coding process is out of contract. Publication, when enabled, is a separate parent-only path that pushes exactly OID:ref after the control plane has already frozen those objects.

Config sketch

{
  "runner_allowed_roots": ["/absolute/root/containing/repos"],
  "runner_max_concurrency": 2,
  "runner_runtime_command": "ltinteg-agent-runner",
  "runner_runtime_timeout_seconds": 3600
}

State and worktree roots default under your platform user-state directory. Hosted images add sandboxing, digest-pinned environments, and registry-session refresh — that is an operator concern, not a laptop default.

Do not put an org-member token or a GitHub PAT in the child environment "to make clone work." If the assignment needs git credentials, the design is wrong — publication stays in the trusted parent.

Tickets

ltinteg-devkit ticket synchronizes local Git facts (branch, HEAD OID, worktree) with Orkestia tickets so the control plane and the laptop agree on the acknowledged head. Use it alongside runner serve when you are the human in the loop for plan acknowledgement.

The group kind is devkit (purpose=agent, integration_type=none). Other kinds: Runner groups.