Configuration
Beside the keys every provider has, a gcp provider reads these.
project
string
project is the Google Cloud project the runners’ instances are created in. It is required.
zones
list of strings
zones are where the instances go, all in one region. Each of a scale set’s runners starts at the zone after its last runner’s, so they spread across them, and a zone out of stock, failing, or without the machine type sends it on to the next. At least one is required.
network
string
network and subnetwork are the VPC network and subnetwork the instances are on, by name or URL. Unset is the project’s default network.
subnetwork
string
See network, above.
external_ip
boolean
external_ip gives each instance an external address, which is how it reaches GitHub unless the network has Cloud NAT. Unset is true.
service_account
string
service_account is the email of the service account the instances run as, and scopes its OAuth scopes. Unset runs them as none. A service account with no scopes gets cloud-platform, which leaves access to the account’s IAM roles.
scopes
list of strings
See service_account, above.
credentials_file
string
credentials_file is the credential Rungar authenticates with, as JSON: a service account key, a workload identity federation configuration (external_account), with no key to leak, or a configuration impersonating a service account. Unset uses Application Default Credentials: the attached service account on Google Cloud, Workload Identity on GKE, or GOOGLE_APPLICATION_CREDENTIALS.
impersonate_service_account
string
impersonate_service_account is the email of a service account Rungar acts as, with short-lived tokens its credentials ask for: the credentials need roles/iam.serviceAccountTokenCreator on the account, and the account needs the roles Rungar does. One identity can then serve several projects, each granting only its own account. Unset acts as the credentials themselves.
timeout
duration, such as 30s or 5m
timeout bounds one call to Compute Engine. Creating a runner, which waits for its instance, is bounded by the scale set’s start_timeout instead, and deleting one by 5 minutes. Unset is 30s.
runner
mapping
The keys of a runner block, the provider’s and each scale set’s for it: a runner is a Compute Engine instance.
runner.machine_type
string, or a list of strings tried in order
machine_type is the instance’s machine type: e2-standard-4, or a custom one such as e2-custom-4-8192. A list, such as [c3-standard-4, n2-standard-4], is tried in order in each zone before the next zone: a zone out of one type, or without it, may have the next, which on Spot finds more capacity than more zones do. It is required, unless instance_template gives it; with one, it is used over the template’s.
The JSON name is the one it had as a string, so that a runner’s revision does not change.
runner.image
string
image is the boot disk’s source image, which must carry the Actions runner: a URL such as projects/my-project/global/images/family/runner, or the name of an image in the provider’s project. It is required, and refused with instance_template, whose disks are the instance’s.
runner.disk_size
size, such as 512MiB or 4GiB
disk_size is the boot disk, where a job’s checkout and build output go, in whole GiB of at least 10GiB. Unset is 50GiB. Refused with instance_template.
runner.disk_type
string
disk_type is the boot disk’s type: pd-balanced, pd-ssd, pd-standard or hyperdisk-balanced. Unset is pd-balanced. Refused with instance_template.
runner.instance_template
string
instance_template is an instance template the instance is created from, for what the other keys do not cover: GPUs, local SSDs, Shielded and Confidential VMs, a minimum CPU platform. It is a URL such as projects/my-project/global/instanceTemplates/runner-gpu, global or in the provider’s region, or the name of a global template in the provider’s project. The template gives the disks, and the network and service account unless the provider sets them; its labels, metadata and network tags are kept, with the runner’s added. A template’s startup-script is replaced by startup_script.
runner.spot
boolean
spot makes the instance a Spot VM: much cheaper, and deleted when Compute Engine needs the capacity back, failing the job it runs. An instance_template’s Spot instances are Spot whatever this says.
runner.network_tags
list of strings
network_tags are the instance’s network tags, which firewall rules select instances by.
runner.labels
mapping of strings
labels are added to the instance’s labels, for billing and search. Keys and values are lower case letters, digits, _ and -, and keys starting rungar_ are Rungar’s.
runner.metadata
mapping of strings
metadata is added to the instance’s metadata. startup-script and the keys starting rungar- are Rungar’s; see startup_script.
runner.startup_script
string
startup_script is the instance’s startup-script: what starts the runner. Unset runs the Actions runner in /home/runner as the runner user, with the registration from the instance’s metadata, and powers the instance off when it exits.