Files
Alexandru MacocianandCopilot 80451af915
Charlie/project-charlie: Build image / config (push) Successful in 2s
Charlie/project-charlie: Deploy runners / config (push) Successful in 0s
Charlie/project-charlie: Deploy runners / deploy-morgott (push) Skipped
Charlie/project-charlie: Deploy runners / deploy-melina (push) Skipped
Charlie/project-charlie: Deploy stack / config (push) Successful in 1s
Charlie/project-charlie: Deploy stack / deploy (push) Skipped
Charlie/project-charlie: Build image / build (push) Successful in 5m57s
Run the agent as an unprivileged user against read-only repos
The entrypoint now mirrors and locks the repo checkout read-only
(root-owned) as root, renders the sherlock config into the copilot
user's home, then drops the service to the jarvis user. The jarvis
binary carries CAP_SETUID/SETGID so the non-root service can spawn the
agent as the separate copilot user.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 5749c447-6ecd-46bd-946d-21b4d101d084
2026-07-30 18:51:25 +02:00
..