Dicer
Runs each runner in a fresh virtual machine on a Dicer host, booted from a container image.
Requirements
dicerdv0.3.0 or later on each host.- A client certificate
dicerdtrusts, or access to its socket.
Configuration
One provider per host. A YAML anchor keeps what they share in one place:
providers:
- &dicer
name: compute1
type: dicer
address: 10.10.0.101:7443
tls:
ca_file: /etc/rungar/ca.pem
cert_file: /etc/rungar/rungar.pem
key_file: /etc/rungar/rungar-key.pem
runner:
image: ghcr.io/actions/actions-runner:latest
- <<: *dicer
name: compute2
address: 10.10.0.102:7443Every key is under Configuration.
Notes
- Without
tls, a TCP address is plaintext and unauthenticated. dicerdlets four vCPUs share each CPU unless itsresources.cpu_overcommitsays otherwise.- A read-write volume can be mounted by one runner at a time.
- Docker in a runner needs its data on a
tmpfsat/var/lib/docker; see running Docker inside an instance.