Skip to content

Trust and verification

Review Gondola before it runs.

Gondola runs inside your AWS account with narrowly defined permission to launch and remove CI runners. This record brings together the public artifacts, data boundaries, verification steps, and assurance limits available before installation.

Public evidence

Start with artifacts, not claims.

IAC / 01

Inspect the infrastructure

The complete Terraform and OpenTofu module is public under Apache 2.0, including controller IAM, runner roles, security groups, launch templates, and coordination resources.

OCI / 02

Inspect the published package

The public OCI package exposes immutable controller images and release bundles. Production configuration requires an image digest rather than a mutable tag.

SIG / 03

Verify before deployment

The installation guide shows how to verify the signed release manifest, image signature, checksums, provenance, and software bills of materials before anything runs.

Data boundary

What reaches Gondola—and what does not.

InformationReceived by GondolaNormal location
Repository source and job outputNoGitHub and the runner inside customer AWS
AWS credentials and GitHub App keyNoCustomer identity systems and secret store
Runner logs and operational metricsNoCustomer-selected CloudWatch destinations
Subscription and entitlement recordsYesGondola fulfillment database; bounded billing fields and cryptographic digests
Full payment-card detailsNoStripe-hosted Checkout
Support correspondenceOnly when sentGondola support systems

The browser-based setup tools do not submit GitHub App keys or AWS credentials to Gondola. Voluntarily supplied support material is handled according to the Privacy Notice.

Evidence boundaries

What each control proves.

ClaimEvidenceLimit
Infrastructure boundaryPublic module source and generated AWS planShows resources and permissions; it does not expose proprietary controller source.
Artifact identityImage digest, signatures, checksums, and provenanceShows which bytes were published by the Gondola release workflow; it is not a claim that software has no defects.
Dependency inventoryPer-binary and image SBOMs plus third-party noticesRecords the build-time inventory; operators must still review and update deployed versions.
Runtime data flowPublished architecture and customer-observable network trafficGondola documents the intended boundary; customers retain their own egress and monitoring controls.
Lifecycle behaviorRelease-gated tests including disposable AWS and GitHub runsThe signed artifacts are public; proprietary source and internal CI logs are not public.

Current assurance status

Precise about what has—and has not—been assessed.

Gondola currently relies on documented boundaries, public infrastructure source, automated analysis, signed supply-chain material, and release-gated AWS/GitHub lifecycle testing. It does not claim SOC 2, ISO 27001, an independent penetration-test attestation, or a 24/7 service-level agreement.