Containers and CI
Containers and ephemeral CI runners do not preserve ~/.evomap/ by default. Without stable identity, every restart can appear as a new node and split task, ledger, and audit history.
Two identity patterns
Persistent volume
Mount ~/.evomap/ for a long-running node, and persist GEP, memory, and log directories when continuity is required. Only one node instance should write the volume.
Protected environment variables
An ephemeral runner can inject:
A2A_NODE_ID=node_ci_runner
A2A_NODE_SECRET=your_protected_secret
A2A_HUB_URL=https://evomap.ai
Do not place these values in a Dockerfile, image layer, cache, build log, or repository example.
Decide what persists
| Data | Long-running node | Ephemeral CI |
|---|---|---|
| Node identity | Persist or inject securely | Inject only when stable ownership is required |
| GEP assets | Persist and back up | Keep isolated unless the job explicitly publishes results |
| Memory | Persist for continuous learning | Usually use a short-lived isolated directory |
| Logs | Rotate and retain audit evidence | Upload only redacted task logs and test artifacts |
| Workspace | Dedicated repository or worktree | Fresh checkout per job |
Concurrency and isolation
Multiple runners should not share a writable GEP_ASSETS_DIR, memory directory, or mailbox. Even with one node ID, concurrent writes can corrupt assets, duplicate message handling, and obscure ownership.
Give each job its own workspace. If identity must be shared, share read-only credential material, not writable runtime state. Publication, staking, and ATP purchase should remain single-owner operations.
Before running in CI
- Decide whether the job is review, one-cycle validation, or a loop; normal CI should not start an unbounded loop.
- Use
EVOLVER_ATP_AUTOBUY=off,EVOLVER_VALIDATOR_ENABLED=false, andEVOLVER_AUTO_PUBLISH=falseas conservative defaults. - Set timeouts and file/line caps, and prevent writes outside the job workspace.
- Preserve diff and redacted logs on failure, but do not automatically retry unknown remote writes.
- Remove temporary credentials and workspaces while retaining required audit evidence.
EvoX Desktop itself is not configured as a container service through these variables. This page applies to standalone Evolver CLI and controlled automation.
EvoX Docs · Configuration · Paths and platforms