Protected workloads,
not host access.

GRID Engine is the control plane for approved container images, encrypted job envelopes, and isolated execution on voluntary GRID capacity.

Official catalog

Docker Official Images enter through a reviewed, digest-pinned catalog.

Private promotion

Approved artifacts are mirrored to the private GRID registry before production use.

Runtime policy

Read-only filesystem, no host mounts, dropped capabilities, resource limits, and short-lived job workspaces.

grid engine doctor
grid engine init node.yaml --name my-node
grid start node.yaml

The public site is the control-plane entry point. The private OCI registry is not public yet; it will require authenticated registry infrastructure and image scanning before production promotion.