{"repo":"helloimalemur/phantomci","free":true,"listed":false,"github":"https://github.com/helloimalemur/phantomci","clone":"git clone https://github.com/helloimalemur/phantomci.git","description":"Secure Headless Self-Hosted Runner","language":"Rust","stars":54,"topics":[],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"🐱 phantom ci ⚙️ Secure, Headless, Self-Hosted CI Runner ✅ Zero unnecessary outbound connections 📤 Output to stdout by default (with optional webhooks) 🔒 Built for minimal trust surfaces --- 🧠 Summary phantom ci is a fully self-hosted CI runner that detects changes in Git repositories and executes pipeline steps defined in a per-branch TOML workflow file. All execution happens locally , as the user who runs phantom ci . No external services are contacted unless explicitly configured. This project was built with isolation and security in mind — specifically to prevent granting inbound or outbound access to unowned servers. --- 🚫 Common CI Tradeoffs vs phantom ci Approach Tradeoff -------------------------------------------------- ---------------------------------------------------- GitHub Actions / SaaS Runners Inbound access from GitHub into your servers GitHub’s Self-Hosted Runners Outbound access to GitHub's infra 3rd-party Runners Implicit outbound connections or exposed APIs ✅ phantom ci No inbound or outbound access required --- 🛡️ Security Posture - Workflows are only run from a locally configured branch ( target branch ) or any branch if left empty. - Branch execution config is stored outside the repo , reducing tampering risk. - CLI-based only — no API, no sockets, no network listeners. - Workflow steps are executed via std::process::Command . If target branch is empty or missing, all branches will be monitored, excluding any listed in branch exclusions . Default","default_branch":null,"files":null,"tree":[],"storefront":"/r/helloimalemur","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/helloimalemur/phantomci/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}