## Architecture at a Glance

Cloud Harness separates request validation from Docker execution authority:

```
[ AI Client ] (OAuth / API Key)
       │
       ▼
[ Credential-Free Ingress Proxy ]
       │
       ▼
[ Stateless MCP API ]
       │ (Authenticated Private RPC)
       ▼
[ Trusted Runner ] ──► [ Docker Authority ] ──► [ Non-Root Executor ]
       │                                              │
       ├─► [ SQLite State Store ]                     └─► [ Isolated Repo Clone ]
       └─► [ GitHub App Broker ] ─(stdin)─► [ Ephemeral Git Helper ]
```

## Quick Endpoints

| Protocol Lane | Public Endpoint | Authentication Method |
|---|---|---|
| **Managed OAuth** | `https://harness.zuey.me/mcp` | Cloudflare Access (GitHub/Google SSO) |
| **Static API Key** | `https://api.harness.zuey.me/mcp` | `Authorization: Bearer <dashboard-api-key>` |
| **Operator Dashboard** | `https://harness.zuey.me/dashboard` | Browser SSO Session |
| **Documentation** | `https://docs.harness.agentkit.best` | Public (Static Pages) |
