# Isolated Forgejo runner image Build the reviewed pinned image and register a repository-scoped runner with only the container label below: ```bash docker build --pull -t argand-site-registry-ci:0.2.0 -f ci/Dockerfile . forgejo-runner register --no-interactive \ --instance https://git.argand.org \ --token REPOSITORY_REGISTRATION_TOKEN \ --name argand-site-registry-isolated \ --labels site-registry-isolated:docker://argand-site-registry-ci:0.2.0 ``` Run the daemon with capacity one, no host label, no bind-volume allowlist, no Docker socket inside jobs, `privileged: false`, and container limits of two CPUs, 4 GiB memory and 4 GiB memory plus swap. The workflow fetches the exact public commit without repository credentials. This runner contains no dataset, reviewer, release-signing or activation authority.