Skip to content
This is the documentation for main, which is not released yet. Read the latest.

Configuration

Beside the keys every provider has, an aws provider reads these.

region

string

region is the AWS region the runners’ instances are created in. It is required.

subnets

list of strings

subnets are the VPC subnets the instances go in, each in one Availability Zone, tried in order: a runner goes to the first that has one of its instance types, and a subnet whose zone is out of capacity sends it to the next. At least one is required.

security_groups

list of strings

security_groups are the IDs of the security groups the instances are in. Unset is the VPC’s default security group.

public_ip

boolean

public_ip gives each instance a public IPv4 address, which is how it reaches GitHub unless the subnet routes through a NAT gateway. Unset is the subnet’s own setting.

instance_profile

string

instance_profile is the IAM instance profile the instances run as, by name or ARN. Unset runs them as none.

profile

string

profile is the named profile, in the shared configuration and credentials files, that Rungar authenticates as. Unset uses the SDK’s default chain: the environment, the default profile, then the role of the ECS task or EC2 instance Rungar runs on.

credentials_file

string

credentials_file is a shared credentials file to read in place of ~/.aws/credentials.

timeout

duration, such as 30s or 5m

timeout bounds one call to EC2. Unset is 30s.

runner

mapping

The keys of a runner block, the provider’s and each scale set’s for it: a runner is an EC2 instance.

runner.instance_type

string, or a list of strings tried in order

instance_type is the instance’s type: m7i.xlarge, c7g.2xlarge. A list, such as [m7i.xlarge, m6i.xlarge], is tried in order in each subnet before the next subnet: a zone out of one type, or without it, may have the next, which on Spot finds more capacity than more subnets do. It is required, unless launch_template gives it; with one, it is used over the template’s.

The JSON name is the one it had as a string, so that a runner’s revision does not change.

runner.image

string

image is the ID of the AMI the instance boots, which must carry the Actions runner and be in the provider’s region: ami-0a1b2c3d4e5f60718. It is required, unless launch_template gives it; with one, it is used over the template’s.

runner.disk_size

size, such as 512MiB or 4GiB

disk_size is the root volume, where a job’s checkout and build output go, in whole GiB: at least the AMI’s snapshot, and at most 64TiB on gp3 or 16TiB on gp2. Unset is 50GiB, or with launch_template, the template’s; setting it there needs image, whose root device it is set on.

runner.disk_type

string

disk_type is the root volume’s type: gp3 or gp2. Unset is gp3, or with launch_template, the template’s; setting it there needs image.

runner.disk_iops

integer

disk_iops is the root volume’s provisioned IOPS, which only gp3 takes: 3000 to 80000, and over 3000 at most 500 per GiB of disk_size. Unset is gp3’s baseline of 3000, or with launch_template, the template’s; setting it there needs image. With launch_template and no disk_type, it is checked against gp3’s limits, and EC2 refuses it if the template’s root volume is gp2.

runner.disk_throughput

integer

disk_throughput is the root volume’s provisioned throughput in MiB/s, which only gp3 takes: 125 to 2000, and over 125 at most 0.25 per IOPS, so 750 at the baseline 3000 IOPS. Unset is gp3’s baseline of 125, or with launch_template, the template’s; setting it there needs image. With launch_template and no disk_type, it is checked against gp3’s limits, against disk_iops only if that is set, and EC2 refuses it if the template’s root volume is not gp3.

runner.launch_template

string

launch_template is an EC2 launch template the instance is created from, for what the other keys do not cover: key pairs, extra volumes, placement groups, capacity reservations. It is the template’s ID or name, followed by a colon and a version for other than its default one: runner-gpu, lt-0a1b2c3d4e5f60718:3, runner-gpu:$Latest. The subnet and user data are always Rungar’s, and the security groups, public IP and instance profile are the provider’s when it sets them; the template’s tags and block devices are kept, with the runner’s added. A template’s security groups go on its network interface, which Rungar’s replaces: EC2 refuses those at its top level. A template’s Spot instances are Spot whatever spot says.

runner.spot

boolean

spot makes the instance a Spot Instance: much cheaper, and terminated when EC2 needs the capacity back, failing the job it runs.

runner.tags

mapping of strings

tags are added to the instance’s and its volumes’ tags, for billing and search. Name, and keys starting rungar.sh/ or aws:, are not allowed.

runner.user_data

string

user_data is the script the instance runs at first boot: what starts the runner. It must start with #!, and Rungar exports the registration as ACTIONS_RUNNER_INPUT_JITCONFIG after that line. It is at most 10KiB, leaving room in EC2’s 16KiB for the registration. Unset runs the Actions runner in /home/runner as the runner user, and powers the instance off when it exits, which terminates it.