Skip to content

Multi-runner scale-set example

This example combines ordinary webhook-managed lanes with one experimental GitHub Actions runner scale-set lane. It demonstrates that v2 keeps the deployment-wide defaults in global_config* and places orchestration and compute-provider settings inside each multi_runner_config lane.

The source example is available at examples/multi-runner-scale-set. Read its README before applying: the GitHub App values are sensitive, the scale-set controller image must be supplied explicitly, and the GitHub scale set/runner group must be authorized for the selected GitHub scope.

Multi-runner scale-set example

This example demonstrates the experimental multi-runner v2 interface. Shared defaults are configured with global_config* variables, while each runner lane uses multi_runner_config for its matcher, runner lifecycle, and compute-provider settings.

The example creates four lanes from one deployment:

  • Linux ARM64 Amazon Linux runners.
  • Ephemeral Linux x64 Amazon Linux runners with job retry enabled.
  • Linux x64 runners managed by a GitHub Actions scale set.
  • Windows x64 Server Core 2022 runners.

The v2 interface keeps provider-owned settings inside the selected provider configuration. For example, VPC and subnet settings are under global_config_compute_provider.aws.ec2, while the per-lane instance types and AMI filter are under each lane's compute provider block.

The scale-set lane uses orchestration_provider.scale_set. Its controller network is configured under the global scale-set block and its GitHub installation ID is provided by var.github_app.

Configure the GitHub App variables before applying:

terraform init
terraform apply \
  -var='github_app={id="123456",key_base64="...",installation_id="123456789"}' \
  -var='github={runner_owner="example",registration_level="organization"}' \
  -var='scale_set={name="linux-scale-set",container={image="ghcr.io/github-aws-runners/terraform-aws-github-runner-scale-set-service@sha256:<release-digest>"}}'

The github_app value is sensitive and should be supplied through a secure variable source in real deployments rather than committed to configuration. The GitHub App must be installed for the configured GitHub account.

Requirements

Name Version
terraform >= 1.5.6
aws >= 6.33
local ~> 2.0
random ~> 3.0

Providers

Name Version
random 3.9.0

Modules

Name Source Version
base ../base n/a
runners ../../modules/multi-runner n/a
webhook_github_app ../../modules/webhook-github-app n/a

Resources

Name Type
random_id.random resource

Inputs

Name Description Type Default Required
ami Optional AMI configuration keyed by runner lane.
map(object({
filter = optional(map(list(string)), { state = ["available"] })
owners = optional(list(string), ["amazon"])
id_ssm_parameter = optional(object({
arn = string
}), null)
kms_key = optional(object({
arn = string
}), null)
}))
{} no
aws_region AWS region to deploy to. string "eu-west-1" no
environment Environment name, used as prefix. string n/a yes
github Optional GitHub endpoint and scale-set ownership settings.
object({
url = optional(string, null)
ssl_verify = optional(bool, true)
runner_owner = optional(string, null)
registration_level = optional(string, "organization")
})
{} no
github_app GitHub App ID, base64-encoded private key, and installation ID.
object({
id = string
key_base64 = string
installation_id = optional(string, null)
})
n/a yes
runner_binaries_enabled Whether runner binary synchronization is enabled. bool true no
scale_set GitHub Actions scale-set configuration.
object({
name = string
runner_group_name = optional(string, "Default")
min_runners = optional(number, 0)
container = optional(object({
image = optional(string, null)
}), {})
})
n/a yes

Outputs

Name Description
webhook_endpoint n/a
webhook_secret n/a