[{"data":1,"prerenderedAt":1602},["ShallowReactive",2],{"navigation":3,"/operations/deployment-models":879,"/operations/deployment-models-surround":1597},[4,22,45,115,156,187,214,235,264,295,318,361,389,418,436,470,491,534,548,571,632,670,693,757,850],{"title":5,"path":6,"stem":7,"children":8,"icon":11},"Introduction","/introduction","01.introduction/1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"What is Orkestia?","i-lucide-sparkles",{"title":13,"path":14,"stem":15,"icon":16},"Core Philosophy","/introduction/core-philosophy","01.introduction/2.core-philosophy","i-lucide-shield-check",{"title":18,"path":19,"stem":20,"icon":21},"Key Benefits","/introduction/key-benefits","01.introduction/3.key-benefits","i-lucide-trophy",{"title":23,"path":24,"stem":25,"children":26,"icon":29},"Getting Started","/getting-started","02.getting-started/1.index",[27,30,35,40],{"title":28,"path":24,"stem":25,"icon":29},"Quick Start","i-lucide-rocket",{"title":31,"path":32,"stem":33,"icon":34},"Architecture Overview","/getting-started/architecture-overview","02.getting-started/2.architecture-overview","i-lucide-layout-dashboard",{"title":36,"path":37,"stem":38,"icon":39},"Concepts at a Glance","/getting-started/concepts","02.getting-started/3.concepts","i-lucide-list",{"title":41,"path":42,"stem":43,"icon":44},"Connect an AI Assistant","/getting-started/connect-an-ai-assistant","02.getting-started/4.connect-an-ai-assistant","i-lucide-bot",{"title":46,"path":47,"stem":48,"children":49,"icon":51},"Core Concepts","/concepts","03.concepts/01.index",[50,52,57,62,67,71,76,81,86,91,96,100,105,110],{"title":46,"path":47,"stem":48,"icon":51},"i-lucide-book-open",{"title":53,"path":54,"stem":55,"icon":56},"Workflows","/concepts/workflows","03.concepts/02.workflows","i-lucide-workflow",{"title":58,"path":59,"stem":60,"icon":61},"DGI — Dialog Generative Interface","/concepts/dgi","03.concepts/03.dgi","i-lucide-brain",{"title":63,"path":64,"stem":65,"icon":66},"Staff & AI Workforce Governance","/concepts/staff-governance","03.concepts/04.staff-governance","i-lucide-users-round",{"title":68,"path":69,"stem":70,"icon":44},"Agents — the execution substrate","/concepts/agents-platform","03.concepts/05.agents-platform",{"title":72,"path":73,"stem":74,"icon":75},"Runners & Execution Environments","/concepts/runners","03.concepts/06.runners","i-lucide-server-cog",{"title":77,"path":78,"stem":79,"icon":80},"Lumen Observability","/concepts/lumen","03.concepts/07.lumen","i-lucide-activity",{"title":82,"path":83,"stem":84,"icon":85},"Identity & Multi-Tenancy","/concepts/identity-multi-tenancy","03.concepts/08.identity-multi-tenancy","i-lucide-users",{"title":87,"path":88,"stem":89,"icon":90},"Billing, Pricing & Seats","/concepts/billing-and-seats","03.concepts/09.billing-and-seats","i-lucide-credit-card",{"title":92,"path":93,"stem":94,"icon":95},"App Data","/concepts/appdata","03.concepts/10.appdata","i-lucide-database",{"title":97,"path":98,"stem":99,"icon":61},"Engram","/concepts/engram","03.concepts/11.engram",{"title":101,"path":102,"stem":103,"icon":104},"DevKit","/concepts/devkit","03.concepts/12.devkit","i-lucide-terminal",{"title":106,"path":107,"stem":108,"icon":109},"App Host","/concepts/app-host","03.concepts/13.app-host","i-lucide-globe",{"title":111,"path":112,"stem":113,"icon":114},"Agent Exchange","/concepts/agent-exchange","03.concepts/14.agent-exchange","i-lucide-landmark",{"title":116,"path":117,"stem":118,"children":119,"icon":121},"Guides","/guides","04.guides/1.index",[120,122,127,132,137,142,147,151],{"title":116,"path":117,"stem":118,"icon":121},"i-lucide-compass",{"title":123,"path":124,"stem":125,"icon":126},"Building with DGI","/guides/building-with-dgi","04.guides/2.building-with-dgi","i-lucide-brain-circuit",{"title":128,"path":129,"stem":130,"icon":131},"Creating & Exposing Virtual Workflows","/guides/virtual-workflows","04.guides/4.virtual-workflows","i-lucide-blocks",{"title":133,"path":134,"stem":135,"icon":136},"Runner Management & Provisioning","/guides/runner-management","04.guides/5.runner-management","i-lucide-server",{"title":138,"path":139,"stem":140,"icon":141},"Security & Compliance","/guides/security-and-compliance","04.guides/7.security-and-compliance","i-lucide-shield",{"title":143,"path":144,"stem":145,"icon":146},"Tickets & Software Delivery","/guides/tickets-and-software-delivery","04.guides/8.tickets-and-software-delivery","i-lucide-ticket",{"title":148,"path":149,"stem":150},"Orkestia for AI-driven cloud infrastructure automation","/guides/cloud-automation-alternatives","04.guides/9.cloud-automation-alternatives",{"title":152,"path":153,"stem":154,"icon":155},"Typed decisions with TypeSafe","/guides/typed-decisions-with-typesafe","04.guides/9.typed-decisions-with-typesafe","i-lucide-git-branch",{"title":157,"path":158,"stem":159,"children":160,"icon":162},"Reference","/reference","05.reference/1.index",[161,163,168,173,177,182],{"title":157,"path":158,"stem":159,"icon":162},"i-lucide-library",{"title":164,"path":165,"stem":166,"icon":167},"Workflow Types & Registry","/reference/workflow-types-registry","05.reference/2.workflow-types-registry","i-lucide-list-tree",{"title":169,"path":170,"stem":171,"icon":172},"MCP Integration","/reference/mcp-integration","05.reference/3.mcp-integration","i-lucide-plug-zap",{"title":174,"path":175,"stem":176,"icon":104},"API & Tooling","/reference/api-tooling","05.reference/4.api-tooling",{"title":178,"path":179,"stem":180,"icon":181},"Integrations Catalog","/reference/integrations-catalog","05.reference/6.integrations-catalog","i-lucide-plug",{"title":183,"path":184,"stem":185,"icon":186},"Platform Services","/reference/platform-services","05.reference/7.platform-services","i-lucide-boxes",{"title":188,"path":189,"stem":190,"children":191,"icon":193},"Advanced Topics","/advanced","06.advanced/1.index",[192,194,199,204,209],{"title":188,"path":189,"stem":190,"icon":193},"i-lucide-flask-conical",{"title":195,"path":196,"stem":197,"icon":198},"Hybrid AI + Deterministic Execution","/advanced/hybrid-execution-model","06.advanced/2.hybrid-execution-model","i-lucide-git-merge",{"title":200,"path":201,"stem":202,"icon":203},"Drift Detection & Self-Healing","/advanced/drift-detection-self-healing","06.advanced/3.drift-detection-self-healing","i-lucide-heart-pulse",{"title":205,"path":206,"stem":207,"icon":208},"Governance & Approvals","/advanced/governance-and-approvals","06.advanced/4.governance-and-approvals","i-lucide-scale",{"title":210,"path":211,"stem":212,"icon":213},"Cost & Performance Optimization","/advanced/cost-and-performance","06.advanced/5.cost-and-performance","i-lucide-zap",{"title":215,"path":216,"stem":217,"children":218,"icon":220},"Operations","/operations","07.operations/1.index",[219,221,225,230],{"title":215,"path":216,"stem":217,"icon":220},"i-lucide-settings-2",{"title":222,"path":223,"stem":224,"icon":186},"Deployment Models","/operations/deployment-models","07.operations/2.deployment-models",{"title":226,"path":227,"stem":228,"icon":229},"Monitoring & Debugging","/operations/monitoring-and-debugging","07.operations/3.monitoring-and-debugging","i-lucide-bug",{"title":231,"path":232,"stem":233,"icon":234},"Best Practices","/operations/best-practices","07.operations/4.best-practices","i-lucide-check-check",{"title":236,"path":237,"stem":238,"children":239,"icon":241},"AWS Connections","/aws-connections","08.aws-connections/1.index",[240,242,245,250,255,260],{"title":236,"path":237,"stem":238,"icon":241},"i-simple-icons-amazonaws",{"title":23,"path":243,"stem":244,"icon":29},"/aws-connections/getting-started","08.aws-connections/2.getting-started",{"title":246,"path":247,"stem":248,"icon":249},"Setup Methods","/aws-connections/setup-methods","08.aws-connections/3.setup-methods","i-lucide-wrench",{"title":251,"path":252,"stem":253,"icon":254},"Managing Connections","/aws-connections/managing-connections","08.aws-connections/4.managing-connections","i-lucide-settings",{"title":256,"path":257,"stem":258,"icon":259},"Security Best Practices","/aws-connections/security-best-practices","08.aws-connections/5.security-best-practices","i-lucide-lock",{"title":261,"path":262,"stem":263,"icon":229},"Troubleshooting","/aws-connections/troubleshooting","08.aws-connections/6.troubleshooting",{"title":265,"path":266,"stem":267,"children":268,"icon":270},"Cloud Connections","/cloud-connections","09.cloud-connections/1.index",[269,271,276,281,286,291],{"title":265,"path":266,"stem":267,"icon":270},"i-lucide-cable",{"title":272,"path":273,"stem":274,"icon":275},"Google Cloud (GCP)","/cloud-connections/gcp","09.cloud-connections/2.gcp","i-simple-icons-googlecloud",{"title":277,"path":278,"stem":279,"icon":280},"Microsoft Azure","/cloud-connections/azure","09.cloud-connections/3.azure","i-simple-icons-microsoftazure",{"title":282,"path":283,"stem":284,"icon":285},"Magalu Cloud","/cloud-connections/magalu","09.cloud-connections/4.magalu","i-lucide-cloud",{"title":287,"path":288,"stem":289,"icon":290},"Kubernetes","/cloud-connections/kubernetes","09.cloud-connections/5.kubernetes","i-simple-icons-kubernetes",{"title":292,"path":293,"stem":294,"icon":208},"TypeSafe","/cloud-connections/typesafe","09.cloud-connections/6.typesafe",{"title":296,"path":297,"stem":298,"children":299,"icon":136},"DNS Providers","/dns-providers","10.dns-providers/1.index",[300,302,305,308,311,315],{"title":301,"path":297,"stem":298,"icon":136},"DNS Provider Connections",{"title":23,"path":303,"stem":304,"icon":29},"/dns-providers/getting-started","10.dns-providers/2.getting-started",{"title":246,"path":306,"stem":307,"icon":249},"/dns-providers/setup-methods","10.dns-providers/3.setup-methods",{"title":251,"path":309,"stem":310,"icon":254},"/dns-providers/managing-connections","10.dns-providers/4.managing-connections",{"title":312,"path":313,"stem":314,"icon":39},"Zones and Records","/dns-providers/zones-and-records","10.dns-providers/5.zones-and-records",{"title":261,"path":316,"stem":317,"icon":229},"/dns-providers/troubleshooting","10.dns-providers/6.troubleshooting",{"title":319,"path":320,"stem":321,"children":322,"icon":29},"Cloud Deploy","/cloud-deploy","11.cloud-deploy/01.index",[323,324,327,332,336,341,345,349,354,358],{"title":319,"path":320,"stem":321,"icon":29},{"title":23,"path":325,"stem":326,"icon":29},"/cloud-deploy/getting-started","11.cloud-deploy/02.getting-started",{"title":328,"path":329,"stem":330,"icon":331},"Creating a Site","/cloud-deploy/creating-a-site","11.cloud-deploy/03.creating-a-site","i-lucide-plus-circle",{"title":333,"path":334,"stem":335,"icon":34},"Site Overview and Deployments","/cloud-deploy/site-overview","11.cloud-deploy/04.site-overview",{"title":337,"path":338,"stem":339,"icon":340},"Deployment Progress and Success","/cloud-deploy/deployment-progress","11.cloud-deploy/05.deployment-progress","i-lucide-loader",{"title":342,"path":343,"stem":344,"icon":254},"Settings","/cloud-deploy/settings","11.cloud-deploy/06.settings",{"title":346,"path":347,"stem":348,"icon":109},"Custom Domains","/cloud-deploy/custom-domains","11.cloud-deploy/07.custom-domains",{"title":350,"path":351,"stem":352,"icon":353},"Resources, Releases, and Danger Zone","/cloud-deploy/resources-releases","11.cloud-deploy/08.resources-releases","i-lucide-package",{"title":355,"path":356,"stem":357,"icon":141},"Admin Dashboard","/cloud-deploy/admin-dashboard","11.cloud-deploy/09.admin-dashboard",{"title":261,"path":359,"stem":360,"icon":229},"/cloud-deploy/troubleshooting","11.cloud-deploy/10.troubleshooting",{"title":362,"path":363,"stem":364,"children":365,"icon":368},"User Onboarding","/user-onboarding","12.user-onboarding/1.index",[366,369,372,377,382,386],{"title":367,"path":363,"stem":364,"icon":368},"User Creation and Onboarding","i-lucide-user-plus",{"title":23,"path":370,"stem":371,"icon":29},"/user-onboarding/getting-started","12.user-onboarding/2.getting-started",{"title":373,"path":374,"stem":375,"icon":376},"Creating Your Organization","/user-onboarding/onboarding","12.user-onboarding/3.onboarding","i-lucide-building-2",{"title":378,"path":379,"stem":380,"icon":381},"Invitations","/user-onboarding/invitations","12.user-onboarding/4.invitations","i-lucide-mail",{"title":383,"path":384,"stem":385,"icon":254},"Managing Your Account","/user-onboarding/managing-account","12.user-onboarding/5.managing-account",{"title":261,"path":387,"stem":388,"icon":229},"/user-onboarding/troubleshooting","12.user-onboarding/6.troubleshooting",{"title":342,"path":390,"stem":391,"children":392,"icon":394},"/settings","13.settings/1.index",[393,395,400,404,409,413],{"title":342,"path":390,"stem":391,"icon":394},"i-lucide-sliders-horizontal",{"title":396,"path":397,"stem":398,"icon":399},"General Settings","/settings/general","13.settings/2.general","i-lucide-user",{"title":401,"path":402,"stem":403,"icon":85},"Members Settings","/settings/members","13.settings/3.members",{"title":405,"path":406,"stem":407,"icon":408},"Notifications Settings","/settings/notifications","13.settings/4.notifications","i-lucide-bell",{"title":410,"path":411,"stem":412,"icon":141},"Security Settings","/settings/security","13.settings/5.security",{"title":414,"path":415,"stem":416,"icon":417},"Signing Keys","/settings/keys","13.settings/6.keys","i-lucide-key-round",{"title":419,"path":420,"stem":421,"children":422,"icon":29},"App Enablement","/app-enablement","14.app-enablement/1.index",[423,424,428,432],{"title":419,"path":420,"stem":421,"icon":29},{"title":425,"path":426,"stem":427,"icon":417},"Sign in with Orkestia","/app-enablement/sign-in-with-orkestia","14.app-enablement/2.sign-in-with-orkestia",{"title":429,"path":430,"stem":431,"icon":95},"End-user data","/app-enablement/end-user-data","14.app-enablement/3.end-user-data",{"title":433,"path":434,"stem":435,"icon":131},"Compositions — use, invoke, share","/app-enablement/compositions","14.app-enablement/4.compositions",{"title":437,"path":438,"stem":439,"children":440,"icon":80},"Lumen","/lumen","15.lumen/1.index",[441,442,447,452,457,461,465],{"title":437,"path":438,"stem":439,"icon":80},{"title":443,"path":444,"stem":445,"icon":446},"Enable Lumen","/lumen/enable","15.lumen/2.enable","i-lucide-power",{"title":448,"path":449,"stem":450,"icon":451},"Send data","/lumen/send-data","15.lumen/3.send-data","i-lucide-upload",{"title":453,"path":454,"stem":455,"icon":456},"Collector","/lumen/collector","15.lumen/4.collector","i-lucide-container",{"title":458,"path":459,"stem":460,"icon":34},"Use Lumen","/lumen/observe","15.lumen/5.observe",{"title":462,"path":463,"stem":464,"icon":44},"Lumen MCP","/lumen/mcp","15.lumen/6.mcp",{"title":466,"path":467,"stem":468,"icon":469},"Query API","/lumen/query-api","15.lumen/7.query-api","i-lucide-search",{"title":471,"path":472,"stem":473,"children":474,"icon":476},"SDKs","/sdks","16.sdks/1.index",[475,477,482,487],{"title":471,"path":472,"stem":473,"icon":476},"i-lucide-code",{"title":478,"path":479,"stem":480,"icon":481},"Workflows SDK — Node / TypeScript","/sdks/workflows-nodejs","16.sdks/2.workflows-nodejs","i-lucide-file-ts",{"title":483,"path":484,"stem":485,"icon":486},"Workflows SDK — Python","/sdks/workflows-python","16.sdks/3.workflows-python","i-simple-icons-python",{"title":488,"path":489,"stem":490,"icon":417},"Auth SDK — Sign in with Orkestia","/sdks/auth","16.sdks/4.auth",{"title":92,"path":492,"stem":493,"children":494,"icon":95},"/appdata","17.appdata/1.index",[495,496,501,506,510,515,520,525,530],{"title":92,"path":492,"stem":493,"icon":95},{"title":497,"path":498,"stem":499,"icon":500},"Declare structures","/appdata/declare","17.appdata/2.declare","i-lucide-table",{"title":502,"path":503,"stem":504,"icon":505},"Records & Data API","/appdata/data-api","17.appdata/3.data-api","i-lucide-rows-3",{"title":507,"path":508,"stem":509,"icon":376},"Ownership & workspaces","/appdata/ownership","17.appdata/4.ownership",{"title":511,"path":512,"stem":513,"icon":514},"Expose App Data to end-users","/appdata/expose","17.appdata/5.expose","i-lucide-app-window",{"title":516,"path":517,"stem":518,"icon":519},"PostgREST HTTP","/appdata/postgrest","17.appdata/6.postgrest","i-lucide-unplug",{"title":521,"path":522,"stem":523,"icon":524},"Ordered append","/appdata/append","17.appdata/7.append","i-lucide-list-ordered",{"title":526,"path":527,"stem":528,"icon":529},"Databases and instances","/appdata/instances","17.appdata/8.instances","i-lucide-hard-drive",{"title":531,"path":532,"stem":533,"icon":104},"Query console and SQL","/appdata/query","17.appdata/9.query",{"title":97,"path":535,"stem":536,"children":537,"icon":61},"/engram","18.engram/1.index",[538,539,543],{"title":97,"path":535,"stem":536,"icon":61},{"title":540,"path":541,"stem":542,"icon":155},"Write & recall","/engram/write-recall","18.engram/2.write-recall",{"title":544,"path":545,"stem":546,"icon":547},"Field & feed","/engram/agent-memory","18.engram/3.agent-memory","i-lucide-radio",{"title":101,"path":549,"stem":550,"children":551,"icon":104},"/devkit","19.devkit/1.index",[552,553,558,562,567],{"title":101,"path":549,"stem":550,"icon":104},{"title":554,"path":555,"stem":556,"icon":557},"Install DevKit","/devkit/install","19.devkit/2.install","i-lucide-download",{"title":559,"path":560,"stem":561,"icon":519},"Hook redirect","/devkit/hooks","19.devkit/3.hooks",{"title":563,"path":564,"stem":565,"icon":566},"Local coding runner","/devkit/local-runner","19.devkit/4.local-runner","i-lucide-cpu",{"title":568,"path":569,"stem":570,"icon":131},"Compositions from DevKit","/devkit/compositions","19.devkit/5.compositions",{"title":572,"path":573,"stem":574,"children":575,"icon":44},"Staff & Agents","/staff-and-agents","20.staff-and-agents/01.index",[576,577,582,586,590,594,598,602,606,611,615,620,625,629],{"title":572,"path":573,"stem":574,"icon":44},{"title":578,"path":579,"stem":580,"icon":581},"Prerequisites","/staff-and-agents/prerequisites","20.staff-and-agents/02.prerequisites","i-lucide-list-checks",{"title":583,"path":584,"stem":585,"icon":368},"Hire an actor","/staff-and-agents/hire-an-actor","20.staff-and-agents/03.hire-an-actor",{"title":587,"path":588,"stem":589,"icon":34},"Console","/staff-and-agents/console","20.staff-and-agents/04.console",{"title":591,"path":592,"stem":593,"icon":11},"Configs, skills, and MCP","/staff-and-agents/configs-skills-mcp","20.staff-and-agents/05.configs-skills-mcp",{"title":595,"path":596,"stem":597,"icon":136},"Agent runner groups","/staff-and-agents/runner-groups","20.staff-and-agents/06.runner-groups",{"title":599,"path":600,"stem":601,"icon":16},"Governance","/staff-and-agents/governance","20.staff-and-agents/07.governance",{"title":603,"path":604,"stem":605,"icon":417},"Identity and tokens","/staff-and-agents/identity","20.staff-and-agents/08.identity",{"title":607,"path":608,"stem":609,"icon":610},"Memory and cost","/staff-and-agents/memory-and-cost","20.staff-and-agents/09.memory-and-cost","i-lucide-wallet",{"title":612,"path":613,"stem":614,"icon":155},"Coding agents","/staff-and-agents/coding-agents","20.staff-and-agents/10.coding-agents",{"title":616,"path":617,"stem":618,"icon":619},"Wire a repository for coding agents","/staff-and-agents/wire-a-repository","20.staff-and-agents/11.wire-a-repository","i-lucide-link",{"title":621,"path":622,"stem":623,"icon":624},"Run a ticket end to end","/staff-and-agents/run-a-ticket","20.staff-and-agents/12.run-a-ticket","i-lucide-play",{"title":626,"path":627,"stem":628,"icon":66},"Build a product team of actors","/staff-and-agents/build-a-product-team","20.staff-and-agents/13.build-a-product-team",{"title":261,"path":630,"stem":631,"icon":249},"/staff-and-agents/troubleshooting","20.staff-and-agents/14.troubleshooting",{"title":106,"path":633,"stem":634,"children":635,"icon":109},"/app-host","21.app-host/1.index",[636,637,641,644,649,653,658,662,666],{"title":106,"path":633,"stem":634,"icon":109},{"title":638,"path":639,"stem":640,"icon":514},"Your app and site","/app-host/your-app","21.app-host/2.your-app",{"title":92,"path":642,"stem":643,"icon":95},"/app-host/app-data","21.app-host/3.app-data",{"title":645,"path":646,"stem":647,"icon":648},"Website and process","/app-host/hosting","21.app-host/4.hosting","i-lucide-cloud-upload",{"title":650,"path":651,"stem":652,"icon":547},"Buzz","/app-host/buzz","21.app-host/5.buzz",{"title":654,"path":655,"stem":656,"icon":657},"Files","/app-host/files","21.app-host/6.files","i-lucide-folder",{"title":659,"path":660,"stem":661,"icon":109},"Your own domain","/app-host/your-domain","21.app-host/7.your-domain",{"title":663,"path":664,"stem":665,"icon":229},"Troubleshooting App Host","/app-host/troubleshooting","21.app-host/8.troubleshooting",{"title":667,"path":668,"stem":669,"icon":417},"Signing keys","/app-host/signing-keys","21.app-host/9.signing-keys",{"title":111,"path":671,"stem":672,"children":673,"icon":114},"/agent-exchange","22.agent-exchange/01.index",[674,675,678,682,686,690],{"title":111,"path":671,"stem":672,"icon":114},{"title":583,"path":676,"stem":677,"icon":368},"/agent-exchange/hire","22.agent-exchange/02.hire",{"title":679,"path":680,"stem":681,"icon":208},"List an actor","/agent-exchange/list","22.agent-exchange/03.list",{"title":683,"path":684,"stem":685,"icon":104},"Invoke & leases","/agent-exchange/invoke","22.agent-exchange/04.invoke",{"title":687,"path":688,"stem":689,"icon":141},"Settlement & trust","/agent-exchange/settlement","22.agent-exchange/05.settlement",{"title":53,"path":691,"stem":692,"icon":56},"/agent-exchange/workflows","22.agent-exchange/06.workflows",{"title":694,"path":695,"stem":696,"children":697,"icon":75},"Runners","/runners","23.runners/1.index",[698,700,704,709,713,717,721,726,730,734,738,741,745,749,753],{"title":699,"path":695,"stem":696,"icon":75},"Runner groups",{"title":701,"path":702,"stem":703,"icon":275},"Cloud Run","/runners/cloud-run","23.runners/10.cloud-run",{"title":705,"path":706,"stem":707,"icon":708},"DigitalOcean App Job","/runners/do-app-job","23.runners/11.do-app-job","i-simple-icons-digitalocean",{"title":710,"path":711,"stem":712,"icon":708},"DigitalOcean Droplet","/runners/do-droplet","23.runners/12.do-droplet",{"title":714,"path":715,"stem":716,"icon":285},"Magalu Cloud VM","/runners/magalu-vm","23.runners/13.magalu-vm",{"title":101,"path":718,"stem":719,"icon":720},"/runners/devkit","23.runners/14.devkit","i-lucide-laptop",{"title":722,"path":723,"stem":724,"icon":725},"Purposes & integrations","/runners/purposes","23.runners/16.purposes","i-lucide-layers",{"title":727,"path":728,"stem":729,"icon":241},"Fargate","/runners/fargate","23.runners/2.fargate",{"title":731,"path":732,"stem":733,"icon":241},"EC2 Auto Scaling","/runners/ec2-auto-scaling","23.runners/3.ec2-auto-scaling",{"title":735,"path":736,"stem":737,"icon":241},"EC2 VM","/runners/ec2-vm","23.runners/4.ec2-vm",{"title":287,"path":739,"stem":740,"icon":290},"/runners/kubernetes","23.runners/5.kubernetes",{"title":742,"path":743,"stem":744,"icon":280},"Azure Container Apps","/runners/azure-container-apps","23.runners/6.azure-container-apps",{"title":746,"path":747,"stem":748,"icon":280},"Azure VMSS","/runners/azure-vmss","23.runners/7.azure-vmss",{"title":750,"path":751,"stem":752,"icon":280},"Azure VM","/runners/azure-vm","23.runners/8.azure-vm",{"title":754,"path":755,"stem":756,"icon":275},"GCE","/runners/gce","23.runners/9.gce",{"title":758,"path":759,"stem":760,"children":761,"icon":763},"Chat","/chat","24.chat/01.index",[762,764,768,773,777,782,787,791,796,800,805,810,814,819,824,828,832,836,840,845],{"title":758,"path":759,"stem":760,"icon":763},"i-lucide-messages-square",{"title":765,"path":766,"stem":767,"icon":446},"Enable and publish","/chat/enable-and-publish","24.chat/02.enable-and-publish",{"title":769,"path":770,"stem":771,"icon":772},"Theme and customization","/chat/theme-and-customization","24.chat/03.theme-and-customization","i-lucide-palette",{"title":774,"path":775,"stem":776,"icon":85},"Members and moderation","/chat/members-and-moderation","24.chat/04.members-and-moderation",{"title":778,"path":779,"stem":780,"icon":781},"Channels","/chat/channels","24.chat/05.channels","i-lucide-hash",{"title":783,"path":784,"stem":785,"icon":786},"Using the chat","/chat/using-the-chat","24.chat/06.using-the-chat","i-lucide-message-circle",{"title":788,"path":789,"stem":790,"icon":44},"Actors in chat","/chat/actors-in-chat","24.chat/07.actors-in-chat",{"title":792,"path":793,"stem":794,"icon":795},"Internal support actor","/chat/internal-support-actor","24.chat/08.internal-support-actor","i-lucide-life-buoy",{"title":797,"path":798,"stem":799,"icon":104},"API and console","/chat/api-and-console","24.chat/09.api-and-console",{"title":801,"path":802,"stem":803,"icon":804},"Limits","/chat/limits","24.chat/10.limits","i-lucide-triangle-alert",{"title":806,"path":807,"stem":808,"icon":809},"Structured chat with DGI","/chat/structured-chat","24.chat/11.structured-chat","i-lucide-layout-list",{"title":811,"path":812,"stem":813,"icon":109},"Option A: hosted chat with DGI","/chat/option-a-hosted-chat","24.chat/12.option-a-hosted-chat",{"title":815,"path":816,"stem":817,"icon":818},"Option B: embed the chat component","/chat/option-b-embed-component","24.chat/13.option-b-embed-component","i-lucide-component",{"title":820,"path":821,"stem":822,"icon":823},"Option C: custom client (wire contract)","/chat/option-c-custom-client","24.chat/14.option-c-custom-client","i-lucide-braces",{"title":825,"path":826,"stem":827,"icon":394},"Responder configuration reference","/chat/responder-reference","24.chat/15.responder-reference",{"title":829,"path":830,"stem":831,"icon":547},"Cards, live updates and proactive posts","/chat/cards-live-and-proactive","24.chat/16.cards-live-and-proactive",{"title":833,"path":834,"stem":835,"icon":16},"Structured chat security model","/chat/structured-chat-security","24.chat/17.structured-chat-security",{"title":837,"path":838,"stem":839,"icon":181},"Option D: any app or API (dgi.chat)","/chat/option-d-chat-api","24.chat/18.option-d-chat-api",{"title":841,"path":842,"stem":843,"icon":844},"Card catalog","/chat/card-catalog","24.chat/19.card-catalog","i-lucide-layout-grid",{"title":846,"path":847,"stem":848,"icon":849},"Living Surfaces","/chat/living-surfaces","24.chat/20.living-surfaces","i-lucide-sprout",{"title":851,"path":852,"stem":853,"children":854,"icon":61},"DGI","/dgi","25.dgi/1.index",[855,857,862,866,870,874],{"title":856,"path":852,"stem":853,"icon":61},"What is DGI",{"title":858,"path":859,"stem":860,"icon":861},"How DGI works","/dgi/how-it-works","25.dgi/2.how-it-works","i-lucide-cog",{"title":863,"path":864,"stem":865,"icon":844},"Interfaces","/dgi/interfaces","25.dgi/3.interfaces",{"title":867,"path":868,"stem":869,"icon":29},"Quickstart","/dgi/quickstart","25.dgi/4.quickstart",{"title":871,"path":872,"stem":873,"icon":16},"Trust and safety","/dgi/trust-and-safety","25.dgi/5.trust-and-safety",{"title":875,"path":876,"stem":877,"icon":878},"FAQ","/dgi/faq","25.dgi/6.faq","i-lucide-circle-help",{"id":880,"title":222,"body":881,"description":1590,"extension":1591,"links":1592,"meta":1593,"navigation":1594,"path":223,"seo":1595,"stem":224,"__hash__":1596},"docs/07.operations/2.deployment-models.md",{"type":882,"value":883,"toc":1580},"minimark",[884,901,919,924,948,955,960,979,983,994,1065,1084,1091,1095,1104,1107,1161,1168,1252,1274,1291,1295,1314,1362,1365,1391,1419,1423,1430,1436,1440,1507,1510,1514,1531,1540,1544,1576],[885,886,887,888,892,893,896,897,900],"p",{},"Orkestia runs as a ",[889,890,891],"strong",{},"split-plane system",": a managed ",[889,894,895],{},"control plane"," that Orkestia operates, and an ",[889,898,899],{},"execution plane"," that lives entirely inside your cloud accounts. The control plane orchestrates, stores workflow state, and observes; it never holds your code or your data. This page explains where each part runs, how your accounts connect, how apps get built and deployed, and exactly where the privacy boundary sits.",[885,902,903,904,908,909,912,913,915,916,918],{},"If you are new to the platform, start with ",[905,906,907],"a",{"href":47},"Concepts"," and the ",[905,910,911],{"href":216},"Deployment overview","; for the connection and deploy walkthroughs see ",[905,914,236],{"href":237}," and ",[905,917,319],{"href":320},".",[920,921,923],"h2",{"id":922},"the-two-planes","The two planes",[925,926,927,938],"card-group",{},[928,929,931],"card",{"icon":75,"title":930},"Control plane (Orkestia-managed)",[885,932,933,934,937],{},"The workflow engine, DGI, Staff governance, Lumen, the MCP surface, and the identity layer. Orkestia runs these. They orchestrate work and store ",[889,935,936],{},"workflow state + observability data"," — never customer source or runtime data.",[928,939,941],{"icon":285,"title":940},"Execution plane (your cloud)",[885,942,943,944,947],{},"Every side-effecting operation — provisioning S3/CloudFront, launching runners, building apps, mutating infrastructure — executes against ",[889,945,946],{},"your"," connected cloud accounts using cross-account roles you grant. The compute and the data stay with you.",[885,949,950,951,954],{},"The boundary is the core design commitment: ",[889,952,953],{},"Zero Code Custody",". Orkestia is a control plane, not a hosting plane. The phrase that recurs across the platform — \"the compute always lives in the customer's cloud; Orkestia holds none of it\" — is literal.",[956,957],"dag-diagram",{":edges":958,":nodes":959},"[{\"from\":\"ENG\",\"to\":\"ROLE\",\"label\":\"assume role, scoped calls\"},{\"from\":\"ROLE\",\"to\":\"S3\"},{\"from\":\"ROLE\",\"to\":\"RUN\"},{\"from\":\"ROLE\",\"to\":\"INFRA\"},{\"from\":\"RUN\",\"to\":\"GH\",\"label\":\"registers directly with\",\"dashed\":true},{\"from\":\"ENG\",\"to\":\"LUMEN\",\"label\":\"state + events only\",\"dashed\":true}]","[{\"id\":\"ENG\",\"label\":\"Workflow engine\",\"sub\":\"(event-sourced state)\",\"kind\":\"engine\"},{\"id\":\"DGI\",\"label\":\"DGI — AI workflow design\",\"kind\":\"ai\"},{\"id\":\"STAFF\",\"label\":\"Staff — agent governance\",\"kind\":\"ai\"},{\"id\":\"LUMEN\",\"label\":\"Lumen — observability\",\"kind\":\"data\"},{\"id\":\"MCP\",\"label\":\"MCP surface\",\"kind\":\"engine\"},{\"id\":\"ID\",\"label\":\"Identity / multi-tenancy\"},{\"id\":\"ROLE\",\"label\":\"Cross-account IAM role\",\"kind\":\"cloud\"},{\"id\":\"S3\",\"label\":\"S3 + CloudFront (apps)\",\"kind\":\"cloud\"},{\"id\":\"RUN\",\"label\":\"Self-hosted runners\",\"sub\":\"ECS/Fargate, EC2, K8s, ...\",\"kind\":\"cloud\"},{\"id\":\"INFRA\",\"label\":\"Your other cloud resources\",\"kind\":\"cloud\"},{\"id\":\"GH\",\"label\":\"GitHub\",\"kind\":\"cloud\"}]",[961,962,963],"note",{},[885,964,965,966,969,970,973,974,978],{},"What the control plane persists: ",[889,967,968],{},"workflow state"," (the event-sourced state machine, run history, DAG structure) and ",[889,971,972],{},"observability data"," (Lumen events/metrics emitted as ",[975,976,977],"code",{},"workflow.transition"," payloads). It does not persist your repository contents, build artifacts, or application runtime data — those stay in your cloud.",[920,980,982],{"id":981},"how-execution-reaches-your-cloud-connections","How execution reaches your cloud: connections",[885,984,985,986,989,990,993],{},"Before Orkestia can do anything in your account, you grant it scoped access through a ",[889,987,988],{},"connection",". For AWS this is a ",[889,991,992],{},"cross-account IAM role"," that the control plane assumes; for GitHub it is an App/OAuth/PAT grant used for repo access, webhooks, and runner registration. Connections are organization-scoped and are the canonical \"prerequisite\" for most workflows.",[995,996,997,1013],"table",{},[998,999,1000],"thead",{},[1001,1002,1003,1007,1010],"tr",{},[1004,1005,1006],"th",{},"Provider",[1004,1008,1009],{},"Mechanism",[1004,1011,1012],{},"What it authorizes",[1014,1015,1016,1028,1043,1054],"tbody",{},[1001,1017,1018,1022,1025],{},[1019,1020,1021],"td",{},"AWS",[1019,1023,1024],{},"Cross-account IAM role (assume-role)",[1019,1026,1027],{},"S3, CloudFront, ACM, Route53, ECS/Fargate, EC2, IAM — per the workflow's needs",[1001,1029,1030,1035,1038],{},[1019,1031,1032],{},[905,1033,1034],{"href":266},"GCP / Azure / Magalu / Kubernetes",[1019,1036,1037],{},"Provider-native credential/grant",[1019,1039,1040,1041],{},"Alternative compute + storage targets — see ",[905,1042,265],{"href":266},[1001,1044,1045,1048,1051],{},[1019,1046,1047],{},"GitHub",[1019,1049,1050],{},"App / OAuth / PAT",[1019,1052,1053],{},"Repo read, webhook registration, short-lived runner registration tokens",[1001,1055,1056,1059,1062],{},[1019,1057,1058],{},"DNS (Route53 / Cloudflare)",[1019,1060,1061],{},"Provider grant",[1019,1063,1064],{},"Custom-domain validation + records",[1066,1067,1068],"tip",{},[885,1069,1070,1071,1074,1075,1078,1079,915,1081,918],{},"The workflow engine knows which connections a capability needs. When you start a workflow whose schema reports ",[975,1072,1073],{},"has_prerequisites: true",", the MCP/",[975,1076,1077],{},"get_workflow_prerequisites"," flow returns a setup guide with Orkestia's own principal pre-filled, so you grant exactly the trust needed — nothing broader. See ",[905,1080,236],{"href":237},[905,1082,1083],{"href":170},"MCP integration",[885,1085,1086,1087,1090],{},"Because access is delegated rather than copied, a broken or revoked connection means that ",[889,1088,1089],{},"app or group simply stops working"," — there is no Orkestia-side fallback that silently holds your resources. This is the privacy boundary expressed operationally.",[920,1092,1094],{"id":1093},"app-deployment-github-your-cloud-cloud-deploy-spad","App deployment: GitHub → your cloud (Cloud Deploy / SPAD)",[885,1096,1097,1099,1100,1103],{},[905,1098,319],{"href":320}," (internally ",[889,1101,1102],{},"SPAD",") is the reference deployment model and the most mature app on the platform. You connect a GitHub repo + branch and a cloud account; Orkestia provisions per-site infrastructure and runs your build pipeline — all inside your account.",[885,1105,1106],{},"For an AWS target, a site is provisioned with isolated, per-site resources:",[995,1108,1109,1119],{},[998,1110,1111],{},[1001,1112,1113,1116],{},[1004,1114,1115],{},"Resource",[1004,1117,1118],{},"Purpose",[1014,1120,1121,1131,1141,1151],{},[1001,1122,1123,1128],{},[1019,1124,1125],{},[975,1126,1127],{},"s3_bucket",[1019,1129,1130],{},"Static asset storage",[1001,1132,1133,1138],{},[1019,1134,1135],{},[975,1136,1137],{},"cloudfront_distribution",[1019,1139,1140],{},"CDN + HTTPS termination",[1001,1142,1143,1148],{},[1019,1144,1145],{},[975,1146,1147],{},"cloudfront_oac",[1019,1149,1150],{},"Origin Access Control (locks the bucket to CloudFront)",[1001,1152,1153,1158],{},[1019,1154,1155],{},[975,1156,1157],{},"acm_certificate",[1019,1159,1160],{},"SSL via ACM, validated through your DNS connection",[885,1162,1163,1164,1167],{},"The build runs on a ",[889,1165,1166],{},"managed build runner in your own cloud"," — not on Orkestia compute. The control plane orchestrates the stages and streams progress; the bytes never leave your account.",[1169,1170,1175],"pre",{"className":1171,"code":1172,"language":1173,"meta":1174,"style":1174},"language-mermaid shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","sequenceDiagram\n  participant GH as GitHub\n  participant CP as Orkestia control plane\n  participant R as Build runner (your cloud)\n  participant AWS as S3 + CloudFront (your cloud)\n\n  GH->>CP: push / release webhook\n  CP->>R: start build (clone → install → build)\n  R->>R: produce artifacts in-account\n  R->>AWS: upload artifacts\n  CP->>AWS: invalidate CloudFront cache\n  CP-->>CP: record deploy state + events\n","mermaid","",[975,1176,1177,1185,1191,1197,1203,1209,1216,1222,1228,1234,1240,1246],{"__ignoreMap":1174},[1178,1179,1182],"span",{"class":1180,"line":1181},"line",1,[1178,1183,1184],{},"sequenceDiagram\n",[1178,1186,1188],{"class":1180,"line":1187},2,[1178,1189,1190],{},"  participant GH as GitHub\n",[1178,1192,1194],{"class":1180,"line":1193},3,[1178,1195,1196],{},"  participant CP as Orkestia control plane\n",[1178,1198,1200],{"class":1180,"line":1199},4,[1178,1201,1202],{},"  participant R as Build runner (your cloud)\n",[1178,1204,1206],{"class":1180,"line":1205},5,[1178,1207,1208],{},"  participant AWS as S3 + CloudFront (your cloud)\n",[1178,1210,1212],{"class":1180,"line":1211},6,[1178,1213,1215],{"emptyLinePlaceholder":1214},true,"\n",[1178,1217,1219],{"class":1180,"line":1218},7,[1178,1220,1221],{},"  GH->>CP: push / release webhook\n",[1178,1223,1225],{"class":1180,"line":1224},8,[1178,1226,1227],{},"  CP->>R: start build (clone → install → build)\n",[1178,1229,1231],{"class":1180,"line":1230},9,[1178,1232,1233],{},"  R->>R: produce artifacts in-account\n",[1178,1235,1237],{"class":1180,"line":1236},10,[1178,1238,1239],{},"  R->>AWS: upload artifacts\n",[1178,1241,1243],{"class":1180,"line":1242},11,[1178,1244,1245],{},"  CP->>AWS: invalidate CloudFront cache\n",[1178,1247,1249],{"class":1180,"line":1248},12,[1178,1250,1251],{},"  CP-->>CP: record deploy state + events\n",[885,1253,1254,1255,1258,1259,1262,1263,1269,1270,1273],{},"A push to the linked branch triggers an auto-deploy workflow; a manual trigger or re-publish runs its own variant; ",[889,1256,1257],{},"rollback re-publishes a prior artifact set without rebuilding",", so it completes in seconds. The engine serializes concurrent deploys of the same site with a Postgres advisory lock, so two quick pushes don't race. See the ",[905,1260,1261],{"href":320},"Cloud Deploy guide"," for the full UX and the ",[905,1264,1268],{"href":1265,"rel":1266},"https://reference.orkestia.dev",[1267],"nofollow","workflow catalog"," for the exact ",[975,1271,1272],{},"spad.*"," workflow names and inputs.",[961,1275,1276],{},[885,1277,1278,1279,1281,1282,1286,1287,1290],{},"AWS is the most mature, fully documented Cloud Deploy target. GCP (GCS + Cloud CDN), Azure, and Cloudflare targets exist as ",[975,1280,1272],{}," provider variants; check ",[905,1283,1285],{"href":1265,"rel":1284},[1267],"the catalog"," for per-provider coverage. Cloud Deploy is ",[889,1288,1289],{},"static / SPA today"," — server-side rendering and edge targets are roadmap, not current scope.",[920,1292,1294],{"id":1293},"compute-deployment-self-hosted-runners","Compute deployment: self-hosted runners",[885,1296,1297,1299,1300,1303,1304,1309,1310,1313],{},[905,1298,694],{"href":695}," provisions ",[889,1301,1302],{},"self-hosted capacity"," inside your cloud (or a DevKit laptop) — the same split-plane shape applied to CI and agent compute. Orkestia is the control plane: it provisions the environment for the group's ",[889,1305,1306],{},[975,1307,1308],{},"backend_type",", optionally mints short-lived registration tokens via a GitHub App or GitLab connection, and drives scaling from a reconcile loop. For GitHub-integrated groups the runner binary ",[889,1311,1312],{},"registers directly with GitHub, not with Orkestia"," — Orkestia only observes.",[995,1315,1316,1326],{},[998,1317,1318],{},[1001,1319,1320,1323],{},[1004,1321,1322],{},"Concept",[1004,1324,1325],{},"Meaning",[1014,1327,1328,1346,1354],{},[1001,1329,1330,1333],{},[1019,1331,1332],{},"Runner group",[1019,1334,1335,1336,1338,1339,1338,1342,1345],{},"Long-lived pool: ",[975,1337,1308],{}," + ",[975,1340,1341],{},"purpose",[975,1343,1344],{},"integration_type"," + scaling policy",[1001,1347,1348,1351],{},[1019,1349,1350],{},"Runner execution",[1019,1352,1353],{},"A single launched runner serving jobs or an agent session on that group",[1001,1355,1356,1359],{},[1019,1357,1358],{},"Scaling",[1019,1360,1361],{},"Reconcile loop converges the pool to the group's min/max; job-source events nudge it to react faster",[885,1363,1364],{},"Key consequences of the model:",[1366,1367,1368,1379,1385],"ul",{},[1369,1370,1371,1374,1375,1378],"li",{},[889,1372,1373],{},"Compute stays in your cloud"," — you pay the provider directly; Orkestia never holds runner compute (",[975,1376,1377],{},"devkit"," is the laptop exception).",[1369,1380,1381,1384],{},[889,1382,1383],{},"No cross-cloud pool"," — a group targets one kind; jobs don't spill from AWS to GCP within a group.",[1369,1386,1387,1390],{},[889,1388,1389],{},"Bounded by policy"," — Orkestia never exceeds your configured max, even under queue pressure, by design.",[1392,1393,1394],"warning",{},[885,1395,1396,1397,1400,1401,1400,1404,1407,1408,1411,1412,915,1415,1418],{},"Kinds are at different maturities. AWS (",[975,1398,1399],{},"fargate",", ",[975,1402,1403],{},"ec2_vm",[975,1405,1406],{},"ec2_auto_scaling",") is GA end-to-end, and ",[889,1409,1410],{},"Azure and Kubernetes groups run production fleets today","; GCP, DigitalOcean, and Magalu kinds have partial coverage. See the ",[905,1413,1414],{"href":695},"kind catalog",[905,1416,1417],{"href":134},"Runner management"," before committing to a beta kind.",[920,1420,1422],{"id":1421},"kubernetes-native-execution","Kubernetes-native execution",[885,1424,1425,1426,1429],{},"Kubernetes is a first-class execution target, not an afterthought. The platform itself runs on Kubernetes, and runner environments can be provisioned as in-cluster Deployments via the Kubernetes runner library. Workflows that touch clusters compose ",[975,1427,1428],{},"k8s.*"," primitives, and the same drift-detection and self-healing model that guards cloud resources applies to Kubernetes objects.",[885,1431,1432,1433,918],{},"This is what lets Orkestia treat \"deploy to my cluster\" and \"deploy to S3+CloudFront\" as the same orchestration shape — different target resources, identical control-plane mechanics (event-sourced state, advisory-lock serialization, Kafka-backed async steps). For how drift and reconciliation work, see ",[905,1434,1435],{"href":201},"Drift detection & self-healing",[920,1437,1439],{"id":1438},"where-state-and-async-live","Where state and async live",[995,1441,1442,1455],{},[998,1443,1444],{},[1001,1445,1446,1449,1452],{},[1004,1447,1448],{},"Concern",[1004,1450,1451],{},"Where it runs",[1004,1453,1454],{},"Notes",[1014,1456,1457,1468,1482,1496],{},[1001,1458,1459,1462,1465],{},[1019,1460,1461],{},"Workflow state machine",[1019,1463,1464],{},"Control plane",[1019,1466,1467],{},"Event-sourced; Postgres advisory locks for concurrency",[1001,1469,1470,1473,1479],{},[1019,1471,1472],{},"Long-running steps (build, upload, provision waits)",[1019,1474,1475,1476,1478],{},"Async via Kafka (",[975,1477,977],{},")",[1019,1480,1481],{},"Consumed by the workflow Kafka consumer — the one async path",[1001,1483,1484,1487,1493],{},[1019,1485,1486],{},"Side effects (cloud mutations, builds)",[1019,1488,1489,1492],{},[889,1490,1491],{},"Your cloud",", via assumed role",[1019,1494,1495],{},"The actual work",[1001,1497,1498,1501,1504],{},[1019,1499,1500],{},"Observability signals",[1019,1502,1503],{},"Control plane (Lumen)",[1019,1505,1506],{},"Events/metrics on the platform Kafka bus",[885,1508,1509],{},"This separation is why a deploy can be slow (e.g. a CloudFront invalidation backlog) without being failed, and why rollback is cheap: the control plane is replaying recorded state, while the heavy lifting already happened — and happened in your account.",[920,1511,1513],{"id":1512},"privacy-boundary-recap","Privacy boundary recap",[1515,1516,1517],"callout",{"icon":16},[885,1518,1519,1522,1523,1526,1527,1530],{},[889,1520,1521],{},"What Orkestia stores:"," workflow state (runs, history, DAGs) and observability data (Lumen).\n",[889,1524,1525],{},"What never leaves your cloud:"," source code, build artifacts, application runtime data, and the compute that produces them.\n",[889,1528,1529],{},"How access works:"," scoped, revocable cross-account roles and provider grants you control — assumed per operation, not copied.",[885,1532,1533,1534,908,1537,918],{},"The result is a control plane you can trust with orchestration and audit, while custody of code and data — and the bill for compute — stays entirely on your side of the line. This is the foundation the rest of the platform builds on: see ",[905,1535,1536],{"href":139},"Security & compliance",[905,1538,1539],{"href":196},"Hybrid execution model",[920,1541,1543],{"id":1542},"where-to-go-next","Where to go next",[925,1545,1546,1551,1556,1565,1570],{},[928,1547,1548],{"icon":241,"title":236,"to":237},[885,1549,1550],{},"Grant Orkestia a scoped cross-account role so it can execute in your AWS account.",[928,1552,1553],{"icon":29,"title":319,"to":320},[885,1554,1555],{},"Deploy apps from GitHub into your own cloud via S3 + CloudFront.",[928,1557,1559],{"icon":186,"title":1558,"to":695},"Runner group kinds",[885,1560,1561,1562,1564],{},"Every ",[975,1563,1308],{}," plus purpose and integration.",[928,1566,1567],{"icon":566,"title":1417,"to":134},[885,1568,1569],{},"Provision and scale self-hosted runners across your clouds.",[928,1571,1573],{"icon":1572,"title":1435,"to":201},"i-lucide-radar",[885,1574,1575],{},"How Orkestia keeps your provisioned resources matching their declared shape.",[1577,1578,1579],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":1174,"searchDepth":1181,"depth":1187,"links":1581},[1582,1583,1584,1585,1586,1587,1588,1589],{"id":922,"depth":1187,"text":923},{"id":981,"depth":1187,"text":982},{"id":1093,"depth":1187,"text":1094},{"id":1293,"depth":1187,"text":1294},{"id":1421,"depth":1187,"text":1422},{"id":1438,"depth":1187,"text":1439},{"id":1512,"depth":1187,"text":1513},{"id":1542,"depth":1187,"text":1543},"How Orkestia splits a managed control plane from execution that runs entirely inside your own cloud accounts","md",null,{},{"icon":186},{"title":222,"description":1590},"5QZ7B55Vas57Dj47G9jDEF5LMGPRcFEpLEa2smQbpMw",[1598,1600],{"title":215,"path":216,"stem":217,"description":1599,"icon":220,"children":-1},"Run Orkestia in production — deployment topologies, monitoring and debugging, and the operational practices that keep workflows reliable",{"title":226,"path":227,"stem":228,"description":1601,"icon":229,"children":-1},"An operational runbook for watching runs, reading history, recovering stuck workflows, and tracing failures with Lumen",1790354045887]