Commit b86c45c8a5

b86c45c8a523684a0b2b303ac7b66099f45951c8

parent: a80064a57d

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-25 18:33 UTC

docs: runner repo access is granted per repo

Layout: unified · split

Admin.org +6
@@ -201,6 +201,12 @@ v1 runs steps directly on the host — no containers — so treat the
201201runner machine as executing whatever your users push. Install the
202202toolchains your builds need on it.
203203
204Instance admin on the runner account only authorizes the claim/report
205protocol; it grants no repo access. A build that pushes back — a pages
206deploy, an archive publish, an automated MR branch — needs an explicit
207grant on that repo: =repo access grant <owner/name> ci write=. Private
208repos likewise need at least read for the clone.
209
204210* Pages
205211
206212=[pages] domain = "example.site"= serves public repos' =pages= branches