Solutions · Platform & DevOps
The infrastructure model, stated directly
This is the technical detail behind RepoFixer's isolation claims, including the one limitation we don't hide: BYOS doesn't yet match managed-server execution guarantees.
Managed vs. BYOS
Servers are either RepoFixer-managed or bring-your-own-server. BYOS keeps your own root access to the box RepoFixer provisions and runs on.
BYOS's current limitation, stated plainly
Real agent execution is currently limited to RepoFixer-managed servers until BYOS reaches the same isolation guarantees. We're not going to imply parity that doesn't exist yet.
Per-server worker authentication
Each server authenticates with its own bearer token, verified on every request. That token is not shared across your fleet.
Worker API is the only boundary
Workers talk only to RepoFixer's Worker API. No worker connects to MongoDB or Redis directly.
Environment Vault
Project secrets are encrypted at rest and scoped per project/environment, with step-up authentication required to reveal one.
Realtime run and deployment status
Agent runs and deployments report status in realtime rather than requiring you to poll for state.
Admin/customer auth separation
The admin console platform operators use is a structurally separate app and auth system; customer accounts can't authenticate there.
Audit and usage visibility
Actions like publishing a change or revealing a Vault secret are recorded to an audit trail. Completed usage/cost records are historical fact and aren't rewritten by later rate or policy changes.
Provisioning and deployment fit the same lifecycle
Provisioning and deployment aren't a separate product. They're part of the same project lifecycle that covers intake, planning, and ongoing backlog maintenance. See the platform overview for how they connect.
FAQ for platform & DevOps
Got backlog work piling up? Tell us about your stack and we'll help you get a first run going.
support@repofixer.com