Secrets store tokens and credentials encrypted with your org’s own key. Jobs and Sandboxes receive them as env vars
and read-only files, values never come back from the API and are redacted from logs, and an env value equal to
a Secret value is refused. type: Registry Secrets pull private images. See Secrets.
Images build from a base plus a few steps or from a Dockerfile, and reuse the digest of an identical earlier
build. Every image is pinned to its digest when you submit work. The catalog has nodus/python,
nodus/pytorch and nodus/agent-tools. See Images.
Volumes keep files across runs as numbered revisions: upload and download with nodus volume, mount them
read-write by one writer, read-only by many, or shared, and import from Hugging Face, git, URLs or S3. See
Volumes.
Connections to Postgres, Neon, Supabase, S3 and Weights & Biases are verified before use and checked daily.
A GitHub Connection installs the Nodus GitHub App so Sandboxes can clone private repositories at a pinned
commit. See Connections.