IAC / 01
Inspect the infrastructure
The complete Terraform and OpenTofu module is public under Apache 2.0, including controller IAM, runner roles, security groups, launch templates, and coordination resources.
Trust and verification
Gondola runs inside your AWS account with narrowly defined permission to launch and remove CI runners. This record brings together the public artifacts, data boundaries, verification steps, and assurance limits available before installation.
Public evidence
IAC / 01
The complete Terraform and OpenTofu module is public under Apache 2.0, including controller IAM, runner roles, security groups, launch templates, and coordination resources.
OCI / 02
The public OCI package exposes immutable controller images and release bundles. Production configuration requires an image digest rather than a mutable tag.
SIG / 03
The installation guide shows how to verify the signed release manifest, image signature, checksums, provenance, and software bills of materials before anything runs.
Data boundary
| Information | Received by Gondola | Normal location |
|---|---|---|
| Repository source and job output | No | GitHub and the runner inside customer AWS |
| AWS credentials and GitHub App key | No | Customer identity systems and secret store |
| Runner logs and operational metrics | No | Customer-selected CloudWatch destinations |
| Subscription and entitlement records | Yes | Gondola fulfillment database; bounded billing fields and cryptographic digests |
| Full payment-card details | No | Stripe-hosted Checkout |
| Support correspondence | Only when sent | Gondola support systems |
The browser-based setup tools do not submit GitHub App keys or AWS credentials to Gondola. Voluntarily supplied support material is handled according to the Privacy Notice.
Evidence boundaries
| Claim | Evidence | Limit |
|---|---|---|
| Infrastructure boundary | Public module source and generated AWS plan | Shows resources and permissions; it does not expose proprietary controller source. |
| Artifact identity | Image digest, signatures, checksums, and provenance | Shows which bytes were published by the Gondola release workflow; it is not a claim that software has no defects. |
| Dependency inventory | Per-binary and image SBOMs plus third-party notices | Records the build-time inventory; operators must still review and update deployed versions. |
| Runtime data flow | Published architecture and customer-observable network traffic | Gondola documents the intended boundary; customers retain their own egress and monitoring controls. |
| Lifecycle behavior | Release-gated tests including disposable AWS and GitHub runs | The signed artifacts are public; proprietary source and internal CI logs are not public. |
Current assurance status
Gondola currently relies on documented boundaries, public infrastructure source, automated analysis, signed supply-chain material, and release-gated AWS/GitHub lifecycle testing. It does not claim SOC 2, ISO 27001, an independent penetration-test attestation, or a 24/7 service-level agreement.