Oore CI
Operate OoreDeployment

Choose a supported deployment

Choose the smallest supported Oore topology for your access, runner, and browser needs.

The default deployment is one customer-owned Mac in Local Only mode. The Complete profile puts the control plane, local web UI, managed Direct macOS runner, and local artifact storage on that Mac. This path needs neither OIDC nor an HTTPS endpoint.

Start with the default

Use the one-Mac installation when everyone who operates Oore can use that Mac’s loopback client. Repository commands run with the managed runner account’s host permissions, so connect only repositories you trust on that account.

Add only the boundary you need

NeedSupported pathOperator-owned boundary
Non-loopback sign-inExternal AccessHTTPS reachability, allowed origins, and OIDC or Trusted Proxy
Oore-hosted browser assetsHosted UIA browser-reachable HTTPS backend
Your own static hostSelf-hosted static UIStatic hosting, TLS, DNS, and CORS
Web UI on another Mac with the product proxySplit roles (advanced)Protected ingress and Web-node-to-control-plane transport
Builds on another MacDirect macOS runnerProtected runner transport and that Mac’s account
Object storageS3 or R2Bucket, credentials, retention, and availability

ci.oore.build is a UI-only static client. It does not host your backend, run builds, proxy API calls, or store server-side credentials and artifacts.

Unsupported and private shapes

The guided v0.1.42 lifecycle supports macOS only. Published Linux web archives are standalone assets, not a guided Web node installation.

Oore V1 does not support a Linux control plane, embedded or hybrid build execution, or raw privileged daemon-service recipes. Oore does not publish its own deployment or release-operations topology as a customer runbook.

Next step

Keep the default one-Mac topology if it meets your needs. Otherwise, follow exactly one task above and verify it before adding another boundary.