See every step.
Trust every build.
Contigra is a production-ready CI/CD platform. Describe your pipeline as a graph, run it across distributed runners, and let every job execute in isolation.
The Contigra stack
Four components. One platform.
Contigra CLI
Initialize, preview, and run pipelines. Built-in health checks and interactive tutorials.
Contigra Server
A gRPC orchestrator with a job queue, runner registry, and mTLS-secured communication.
Contigra Runner
Distributed job execution with tag-based routing and sandboxed containers.
MCP Server
Expose your pipelines to AI tooling through the Model Context Protocol.
Why Contigra
Built for teams that ship.
Fast by design
DAG scheduling with parallel execution, and a content-based cache with LRU, LFU, and usage-based eviction.
Secure by default
mTLS between every component, non-root containers, dropped capabilities, and full audit logging.
Distributed
Runners register themselves, report health, and receive work matched to their capabilities.
Observable
Built-in health checks, distributed tracing, and structured real-time execution logs.
Pipelines as code
Readable, declarative, reproducible.
Define stages, dependencies, environment variables, and timeouts in a single TOML file. Contigra resolves the graph and runs independent work in parallel.
# contigra.toml [pipeline] name = "rust-service" [[pipeline.stages]] name = "validate" [[pipeline.stages.steps]] name = "audit" command = "cargo audit" [[pipeline.stages]] name = "build" depends_on = ["validate"] [[pipeline.stages.steps]] name = "compile" command = "cargo build --release" timeout_seconds = 600
How it works
From commit to result, in four moves.
Describe
Write stages and dependencies in contigra.toml.
Resolve
Contigra builds the execution graph and orders it topologically.
Dispatch
The server queues jobs and matches them to runners by tag and load.
Execute
Runners run each job in a sandboxed container and report back.
Security
Zero-trust, from the first request.
Every component authenticates every other one. Every job runs with the least privilege it needs.
- Mutual TLS between the CLI, server, and runners
- Non-root containers with a read-only filesystem and dropped capabilities
- JWT and API key authentication
- Audit logging of security events
# start the orchestrator with mTLS $ contigra-server \ --config contigra-server.toml \ --enable-mtls \ --mtls-domain contigra.example.com # connect a runner $ contigra-runner \ --server http://localhost:50051 \ --tags rust,docker \ --max-jobs 4
Start fast
Bring what you already have.
Six starter templates
Rust, Node.js, Python, Docker, Kubernetes, or a minimal skeleton. Pick one with contigra init --template.
From GitHub Actions
Convert existing workflows to Contigra format with contigra migrate, or run GitHub Actions-style workflows locally.
A recipe cookbook
Browse, search, and generate pipelines from curated patterns with contigra cookbook.
Get started
From zero to pipeline in minutes.
Define
Create a pipeline from a template.
$ contigra init --template rustPreview
See the execution graph before anything runs.
$ contigra planRun
Execute stages in parallel, locally or on runners.
$ contigra runScale
Add a server and connect runners as you grow.
$ contigra-server --enable-mtlsFAQ
Questions, answered.
Can I run Contigra without a server?
Yes. The CLI runs pipelines entirely on your machine. Add a server and runners when you need shared capacity.
What do I need to run jobs in containers?
Docker or Podman. Jobs run in sandboxed containers with non-root users and a read-only filesystem.
How are pipelines defined?
In a TOML file, contigra.toml, with stages, steps, and depends_on relationships between stages.
Does it work with AI tools?
Contigra ships an MCP server, so AI tools that speak the Model Context Protocol can work with your pipelines.
Who builds Contigra?
Contigra is built and maintained by Nuvai.
Ready to ship with confidence?
Learn how Contigra works, from pipelines to runners, in the docs.