DL-325
The runner end state splits by trust model (RIG-3070): untrusted multi-tenant operation requires the microVM hardware boundary (KVM, unchanged); self-host single-tenant deployments keep podman as a permanent, supported entry tier requiring no /dev/kvm, with microVM the recommended (not required) upgrade for defense-in-depth or an operator running untrusted code. When and how a hosted multi-tenant service sequences its move to microVM-only is a managed-plane rollout decision, out of scope here. AMENDS the frozen KVM-only amendment (microvm-kvm-only-amendment.md:96-97, “A KVM-absent host does not get a lesser boundary; it does not run”) with a self-host carve-out; RATIFIES DL-259’s stack SHAPE (host-level bring-up, no compose/Swarm) and PARTIAL-SUPERSEDES its KVM-machine clause BY CITATION for the podman entry tier (matching DL-319’s treatment of the same clause; DL-259 stays Active); the ContainerRuntime interface stays frozen; DL-235’s client-only charter is REVERSED by DL-319 (the compass-native embedded-mode-revival record, ui/compass-native-embedded-revival/design.md), which carries this record’s trust-model rationale, and this record does not itself alter compass-app architecture
Status: Active (Matt, 2026-08-31)
Record: ../../infra/runtime/compass-runner-adoption-strategy/design.md#the-ruled-topology