Runa never borrows your session
An assistant that can query a database or restart a workload needs a narrower answer to “who is doing this?” than “whoever is logged in”.
Read more →Blog
How we think about deploys, storage, images, AI access, automation and the fleet — and the decisions behind each.
An assistant that can query a database or restart a workload needs a narrower answer to “who is doing this?” than “whoever is logged in”.
Read more →Why every deployment on Sites is kept whole with its own address — and what that buys you at 2 a.m.
Read more →Why Subnomic Storage is the S3 API rather than an SDK of its own — and what it refuses instead of faking.
Read more →What the registry scans, what it shows, and why it deliberately doesn’t block your push.
Read more →Workflows run as a credential, stop for approval, and resume after a crash without sending the same command twice.
Read more →A small contract in the Subnomic CLI, and why one friendly line would break every pipeline that relies on it.
Read more →How an outbound-only agent lets you open a terminal on every host while port 22 stays closed to the internet.
Read more →Session replay turns “who did what” from guesswork into a recording you can scrub through during an incident.
Read more →A practical model for scoping people, automation and AI to what they need — with access that expires on its own.
Read more →CPU, memory, disk, processes and network from every host — over the same connection that carries access.
Read more →Why sign-in uses passkeys, and why every credential a machine holds is scoped, can expire and is shown only once.
Read more →More posts coming soon.