Operator documentation
Generated from this repository's docs/architecture/ tree (how-to, reference, tutorial) -- always in sync with the source checked into the repo.
Configuration and operations
- Alpha testing runbook — local stack
- Configure OCI pull-through with verified upstream
- Configure PyPI pull-through with verified upstream
- Configure npm pull-through with verified upstream
- Curator workflow — waive, block, exclude
- Declare configuration via $HORT_CONFIG_DIR (gitops)
- Enable Sigstore/cosign provenance verification
- Federate CI runners (GitHub Actions, GitLab CI) to hort-server
- Federate a k8s workload to hort-server via projected SA tokens
- How to Add a Format Handler
- Install hort-cli
- Licenses and third-party attribution
- Recovering stranded artifacts
- Release a security-fix from quarantine
- Rotate service-account PATs via the worker reconciler
- Shell completions for hort-cli
- Tune HTTP transport timeouts
- Using hort-cli for admin operations
- Verify a release with cosign verify-blob
- Wire secrets for UpstreamMapping.secretRef:
Deployment
- Admin identity and the Dex bootstrap
- Enable admin-task CronJobs (scheduledTasks.adminTasksEnabled)
- Extra CA bundle — trusting internal or corporate CAs
- Install hort-server + hort-worker on a single Linux host
- Install hort-server fully sovereign against registry.hort.rs
- Install hort-server on Kubernetes
- control-plane-tiers.md — the three exposure tiers, egress posture, and the control-plane listener
- hort-server Helm chart — edge overlays
- hort-server Helm chart — values reference
- postgres-roles.md — Provisioning the Postgres roles
- security-hardening-checklist.md — the chart's security controls
Operate
- Mint a least-privilege reader token for a Kubernetes imagePullSecret
- Operating claim-based RBAC
- Operating the public supply-chain deployment (registry.hort.rs)
Reference
- Public event taxonomy
- Reference — hort-server and hort-worker configuration
- Reference — the hort-server Helm chart