Configuration
Beside the keys every provider has, an aws provider reads these.
region
string
region is the AWS region the runners’ instances are created in. It is required.
subnets
list of strings
subnets are the VPC subnets the instances go in, each in one Availability Zone, tried in order: a runner goes to the first that has one of its instance types, and a subnet whose zone is out of capacity sends it to the next. At least one is required.
security_groups
list of strings
security_groups are the IDs of the security groups the instances are in. Unset is the VPC’s default security group.
public_ip
boolean
public_ip gives each instance a public IPv4 address, which is how it reaches GitHub unless the subnet routes through a NAT gateway. Unset is the subnet’s own setting.
instance_profile
string
instance_profile is the IAM instance profile the instances run as, by name or ARN. Unset runs them as none.
profile
string
profile is the named profile, in the shared configuration and credentials files, that Rungar authenticates as. Unset uses the SDK’s default chain: the environment, the default profile, then the role of the ECS task or EC2 instance Rungar runs on.
credentials_file
string
credentials_file is a shared credentials file to read in place of ~/.aws/credentials.
timeout
duration, such as 30s or 5m
timeout bounds one call to EC2. Unset is 30s.
runner
mapping
The keys of a runner block, the provider’s and each scale set’s for it: a runner is an EC2 instance.
runner.instance_type
string, or a list of strings tried in order
instance_type is the instance’s type: m7i.xlarge, c7g.2xlarge. A list, such as [m7i.xlarge, m6i.xlarge], is tried in order in each subnet before the next subnet: a zone out of one type, or without it, may have the next, which on Spot finds more capacity than more subnets do. It is required, unless launch_template gives it; with one, it is used over the template’s.
The JSON name is the one it had as a string, so that a runner’s revision does not change.
runner.image
string
image is the ID of the AMI the instance boots, which must carry the Actions runner and be in the provider’s region: ami-0a1b2c3d4e5f60718. It is required, unless launch_template gives it; with one, it is used over the template’s.
runner.disk_size
size, such as 512MiB or 4GiB
disk_size is the root volume, where a job’s checkout and build output go, in whole GiB: at least the AMI’s snapshot, and at most 64TiB on gp3 or 16TiB on gp2. Unset is 50GiB, or with launch_template, the template’s; setting it there needs image, whose root device it is set on.
runner.disk_type
string
disk_type is the root volume’s type: gp3 or gp2. Unset is gp3, or with launch_template, the template’s; setting it there needs image.
runner.disk_iops
integer
disk_iops is the root volume’s provisioned IOPS, which only gp3 takes: 3000 to 80000, and over 3000 at most 500 per GiB of disk_size. Unset is gp3’s baseline of 3000, or with launch_template, the template’s; setting it there needs image. With launch_template and no disk_type, it is checked against gp3’s limits, and EC2 refuses it if the template’s root volume is gp2.
runner.disk_throughput
integer
disk_throughput is the root volume’s provisioned throughput in MiB/s, which only gp3 takes: 125 to 2000, and over 125 at most 0.25 per IOPS, so 750 at the baseline 3000 IOPS. Unset is gp3’s baseline of 125, or with launch_template, the template’s; setting it there needs image. With launch_template and no disk_type, it is checked against gp3’s limits, against disk_iops only if that is set, and EC2 refuses it if the template’s root volume is not gp3.
runner.launch_template
string
launch_template is an EC2 launch template the instance is created from, for what the other keys do not cover: key pairs, extra volumes, placement groups, capacity reservations. It is the template’s ID or name, followed by a colon and a version for other than its default one: runner-gpu, lt-0a1b2c3d4e5f60718:3, runner-gpu:$Latest. The subnet and user data are always Rungar’s, and the security groups, public IP and instance profile are the provider’s when it sets them; the template’s tags and block devices are kept, with the runner’s added. A template’s security groups go on its network interface, which Rungar’s replaces: EC2 refuses those at its top level. A template’s Spot instances are Spot whatever spot says.
runner.spot
boolean
spot makes the instance a Spot Instance: much cheaper, and terminated when EC2 needs the capacity back, failing the job it runs.
runner.tags
mapping of strings
tags are added to the instance’s and its volumes’ tags, for billing and search. Name, and keys starting rungar.sh/ or aws:, are not allowed.
runner.user_data
string
user_data is the script the instance runs at first boot: what starts the runner. It must start with #!, and Rungar exports the registration as ACTIONS_RUNNER_INPUT_JITCONFIG after that line. It is at most 10KiB, leaving room in EC2’s 16KiB for the registration. Unset runs the Actions runner in /home/runner as the runner user, and powers the instance off when it exits, which terminates it.