Skip to content
This is the documentation for main, which is not released yet. Read the latest.

Configuration

Beside the keys every provider has, a gcp provider reads these.

project

string

project is the Google Cloud project the runners’ instances are created in. It is required.

zones

list of strings

zones are where the instances go, all in one region. Each of a scale set’s runners starts at the zone after its last runner’s, so they spread across them, and a zone out of stock, failing, or without the machine type sends it on to the next. At least one is required.

network

string

network and subnetwork are the VPC network and subnetwork the instances are on, by name or URL. Unset is the project’s default network.

subnetwork

string

See network, above.

external_ip

boolean

external_ip gives each instance an external address, which is how it reaches GitHub unless the network has Cloud NAT. Unset is true.

service_account

string

service_account is the email of the service account the instances run as, and scopes its OAuth scopes. Unset runs them as none. A service account with no scopes gets cloud-platform, which leaves access to the account’s IAM roles.

scopes

list of strings

See service_account, above.

credentials_file

string

credentials_file is the credential Rungar authenticates with, as JSON: a service account key, a workload identity federation configuration (external_account), with no key to leak, or a configuration impersonating a service account. Unset uses Application Default Credentials: the attached service account on Google Cloud, Workload Identity on GKE, or GOOGLE_APPLICATION_CREDENTIALS.

impersonate_service_account

string

impersonate_service_account is the email of a service account Rungar acts as, with short-lived tokens its credentials ask for: the credentials need roles/iam.serviceAccountTokenCreator on the account, and the account needs the roles Rungar does. One identity can then serve several projects, each granting only its own account. Unset acts as the credentials themselves.

timeout

duration, such as 30s or 5m

timeout bounds one call to Compute Engine. Creating a runner, which waits for its instance, is bounded by the scale set’s start_timeout instead, and deleting one by 5 minutes. Unset is 30s.

runner

mapping

The keys of a runner block, the provider’s and each scale set’s for it: a runner is a Compute Engine instance.

runner.machine_type

string, or a list of strings tried in order

machine_type is the instance’s machine type: e2-standard-4, or a custom one such as e2-custom-4-8192. A list, such as [c3-standard-4, n2-standard-4], is tried in order in each zone before the next zone: a zone out of one type, or without it, may have the next, which on Spot finds more capacity than more zones do. It is required, unless instance_template gives it; with one, it is used over the template’s.

The JSON name is the one it had as a string, so that a runner’s revision does not change.

runner.image

string

image is the boot disk’s source image, which must carry the Actions runner: a URL such as projects/my-project/global/images/family/runner, or the name of an image in the provider’s project. It is required, and refused with instance_template, whose disks are the instance’s.

runner.disk_size

size, such as 512MiB or 4GiB

disk_size is the boot disk, where a job’s checkout and build output go, in whole GiB of at least 10GiB. Unset is 50GiB. Refused with instance_template.

runner.disk_type

string

disk_type is the boot disk’s type: pd-balanced, pd-ssd, pd-standard or hyperdisk-balanced. Unset is pd-balanced. Refused with instance_template.

runner.instance_template

string

instance_template is an instance template the instance is created from, for what the other keys do not cover: GPUs, local SSDs, Shielded and Confidential VMs, a minimum CPU platform. It is a URL such as projects/my-project/global/instanceTemplates/runner-gpu, global or in the provider’s region, or the name of a global template in the provider’s project. The template gives the disks, and the network and service account unless the provider sets them; its labels, metadata and network tags are kept, with the runner’s added. A template’s startup-script is replaced by startup_script.

runner.spot

boolean

spot makes the instance a Spot VM: much cheaper, and deleted when Compute Engine needs the capacity back, failing the job it runs. An instance_template’s Spot instances are Spot whatever this says.

runner.network_tags

list of strings

network_tags are the instance’s network tags, which firewall rules select instances by.

runner.labels

mapping of strings

labels are added to the instance’s labels, for billing and search. Keys and values are lower case letters, digits, _ and -, and keys starting rungar_ are Rungar’s.

runner.metadata

mapping of strings

metadata is added to the instance’s metadata. startup-script and the keys starting rungar- are Rungar’s; see startup_script.

runner.startup_script

string

startup_script is the instance’s startup-script: what starts the runner. Unset runs the Actions runner in /home/runner as the runner user, with the registration from the instance’s metadata, and powers the instance off when it exits.