Skip to main content
Namespace provides ephemeral, self-hosted Buildkite agents without requiring you to operate agent infrastructure. Prefer to manage the integration through Buildkite? Buildkite Hosted Agents use Namespace infrastructure and are configured directly in Buildkite. Learn about Buildkite Hosted Agents →

How it works

Connecting a Buildkite organization creates a Namespace-managed queue and an agent token in either a new Namespace Cluster or an existing Buildkite cluster. A Buildkite webhook notifies Namespace when a job is scheduled on that cluster. Namespace then provisions an isolated instance, starts an agent for the queue, runs the job, and tears the instance down when the job completes. You can select the operating system, architecture, instance shape, base image, and persistent cache for each step using agent tags.
Buildkite agents are a limited-access feature, reach out to get enrolled into Namespace-managed agents.Contact support →

Getting Started

1

Create a Buildkite API access token

Create an API access token for the Buildkite organization you want to connect. Namespace uses this token for initial setup, ongoing build reconciliation, and build annotations, so its expiry must be set to Never. The token can be revoked at any time through the Buildkite UI. Enable these REST API scopes:
  • read_pipelines
  • read_builds and write_builds
  • read_clusters and write_clusters
  • read_organizations
The “No organization” access option is not supported. Make sure that you select a valid organization for your token.
2

Connect your Buildkite organization

Open Buildkite → Get started in the Namespace dashboard. If another organization is already connected, select Connect organization from the Organizations page instead.Enter the API token and click Next. Namespace uses the token to identify your Buildkite organization and list its clusters.
3

Select a cluster and queue

Choose where Namespace should create its managed queue:
  • Select Create a new cluster to create the Namespace Cluster with a default queue.
  • Select an existing cluster to add a queue to it. Enter a queue name, or keep the default name, namespace.
Configure any optional connection settings, then click Associate. Namespace creates the cluster if needed, creates the queue and its agent token, and displays the webhook setup instructions. Copy the generated webhook URL for the next step.
4

Configure the Buildkite webhook

On the next page, click on Create new Webhook and copy and paste the provided webhook URL and token.
Buildkite webhook configuration for Namespace
Select the following events in the Buildkite webhook interface:
  • ping
  • job.scheduled
  • job.started
  • job.finished
Buildkite webhook events configuration for Namespace
Make sure the webhook is enabled for All Pipelines.
Buildkite pipelines configuration for Namespace
Click Add Webhook Notification, then return to Namespace. The connection becomes active after Namespace receives the webhook ping.
5

Add a pipeline to the selected cluster

In your Buildkite pipeline’s settings, select the cluster you chose during setup under General > Cluster. If you added a queue to an existing cluster, set the pipeline or step’s queue agent tag to the queue name you chose:

Checking out code from GitHub & Cursor Origin

Namespace checks out your repository before each Buildkite job runs. Public repositories work with no extra configuration; private repositories need credentials, as described below.

Cloning with HTTPS

Cloning public repositories over HTTPS requires no additional configuration. To clone private GitHub repositories, add your GitHub credentials to your Buildkite organization in Namespace:
  1. Connect your GitHub account through Code providers.
  2. Open Buildkite → Organizations in the Namespace dashboard and select your Buildkite organization.
  3. Click Edit Secrets, then Add another secret.
  4. Select GitHub Credentials from the dropdown, select your GitHub account, and then click Save Variables.
Namespace will now use short-lived credentials provided by the GitHub App integration to check out code. To clone a private Cursor Origin repository:
  1. Connect Buildkite to Cursor so Cursor can start Buildkite jobs for the repository.
  2. Connect Cursor Origin through Code Providers so Namespace can check out the repository.
  3. Configure the pipeline to use a Namespace-managed queue as described in Getting Started.

Cloning with SSH

You can configure cloning over SSH by uploading your private key either to Namespace Vault or as a secret in Buildkite. Currently, signed pipelines with SSH checkout are supported only with secrets stored in Namespace.
Cloning over SSH is not supported yet for Cursor Origin repositories.
To configure cloning over SSH in Namespace:
  1. Upload your private key as a secret, using either the Vault dashboard or CLI command
  1. In the Namespace dashboard, click on Edit Secrets and then Add another secret.
  2. Select SSH Key from the dropdown, select your key, and then click Save Variables.
SSH private key configuration
If you prefer to store your SSH key in Buildkite, follow Buildkite’s code access setup for self-hosted agents. Store your private key as a Buildkite secret, then set checkout.ssh_secret on each of your pipeline’s steps that require SSH access:

Git snapshots

For faster checkouts of large GitHub or Cursor Origin repositories, jobs can use a pre-fetched snapshot instead of a Git clone. See Git Snapshots.

Next Steps

Managing Queues. Register additional Buildkite queues with Namespace, route jobs to them, and unregister the ones you no longer need. Configure Buildkite Agents. Choose compute resources, base images, and persistent caches with agent tags.
Last modified on September 29, 2026