Architecture & The Runner

What is the difference between the build runner and an install runner?
How is the runner secure?
Does the runner run inside the installed app?
How does the runner get updated?
What happens if the runner fails?
How does Nuon handle deployments requiring external infrastructure components (e.g., DNS, networking)?
Can egress connectivity from the customer install be disabled?
How does Nuon compare to other multi-cloud orchestration platforms?
Do you support GitHub, GitLab & Bitbucket?
Why doesn't AWS or other clouds offer this?
Is the CloudFormation template just to set up the Nuon runner, or does it also set up part of our application?
Can the Nuon control plane run air-gapped?
What are the minimum customer requirements to deploy an app with Nuon?
What are the key components inside the runner VM - is ClickHouse and Temporal running in there?
Does the runner VM need internet access to stream logs back?
Does the runner pulls everything down to the machine in the customer network, installs tools like terraform and helm, runs them, and then stays running as a control plane?
Walk through the artifact flow - if we have terraform, helm charts, and container images, how does that work with Nuon?
In open source vs Nuon Cloud, do you lose the dashboard?
If a customer doesn't allow any external access, are there trade-offs or can it run fully locally?
Do I have to use Nuon's hosted cloud, or can I run the control plane in my own cloud?
How does the runner architecture work?
Where does the runner actually run?
How are runner permissions handled?
Who is responsible for what in a BYOC deployment?
I added and enabled a new role, but the runner isn't picking it up. Why, and what do I do?