Skip to content
This is the documentation for main, which is not released yet. Read the latest.

Configuration

Beside the keys every provider has, a dicer provider reads these.

address

string

address is where the Dicer daemon is, as a gRPC target: “10.0.0.1:7443” for its TCP listener, or “unix:///run/dicer/dicer.sock” for its socket on this machine.

timeout

duration, such as 30s or 5m

timeout bounds one call to the daemon, except pulling a runner’s image onto the host, which can take minutes and is bounded by the scale set’s start_timeout instead. Unset is 10s.

tls

mapping

tls is how the daemon is verified and how Rungar identifies itself to it. Without it, a TCP connection is plaintext and unauthenticated. It is refused on a unix:// address, which the socket’s permissions protect instead.

tls.cert_file

string

cert_file and key_file are Rungar’s certificate and private key, in PEM. Give both or neither.

tls.key_file

string

See cert_file, above.

tls.ca_file

string

ca_file holds the PEM authorities the daemon’s certificate is checked against. Empty uses this machine’s root CAs.

tls.server_name

string

server_name is the name the daemon’s certificate must carry. Empty uses the host from its address.

runner

mapping

The keys of a runner block, the provider’s and each scale set’s for it: a runner is a virtual machine booted from a container image. A name given here – a kernel, a network, a volume – must exist on every host the block is given to.

runner.image

string

image is the container image the instance boots from, which must carry the Actions runner, as ghcr.io/actions/actions-runner does. Pinning it to a digest, runner:latest@sha256:…, has every runner boot exactly that image. It is required.

runner.command

list of strings

command is what the instance runs. Unset is the runner image’s start script, /home/runner/run.sh.

runner.vcpus

integer

vcpus is how many virtual CPUs the instance has. It is required.

runner.memory

size, such as 512MiB or 4GiB

memory is the instance’s memory, written as a size: 4GiB. A plain number is bytes. It is required, at least 128MiB, and a whole number of MiB, which the hypervisor needs.

runner.disk

size, such as 512MiB or 4GiB

disk is the instance’s root disk, where a job’s checkout and build output go. It is sparse, so what a job does not use costs the host nothing. Unset is 20GiB.

runner.kernel

string

kernel is the kernel the instance boots, as the host names it. Unset takes the host’s default. A name given must exist on every host the runner may land on.

runner.network

string

network is the network the instance joins, as the host names it. Unset takes the host’s default. A name given must exist on every host the runner may land on.

runner.env

mapping of strings

env is added to the runner’s environment. The variables that register the runner with GitHub override anything set here.

runner.mounts[]

list of mappings

mounts are attached to the instance, named as they are on the host: a build cache volume, a CA bundle.

runner.mounts[].type

string: volume, file or tmpfs

type is volume, file or tmpfs.

runner.mounts[].source

string

source is the volume’s name, or the host file’s absolute path. A tmpfs has none.

runner.mounts[].target

string

target is the absolute path the mount appears at in the instance.

runner.mounts[].read_only

boolean

read_only mounts it read-only. A volume several runners mount at once must be mounted read-only by every one of them.