Context
Follow-up documentation work for PR #5299, which adds experimental GitHub Actions runner scale-set support.
The current documentation does not fully explain the scale-set architecture, configuration options, security boundaries, or operational behavior.
Scope
Update the documentation to cover:
- The overall architecture and request/lifecycle flow:
- Terraform scale-set orchestration
- ECS controller service
- SSM configuration and secret references
- GitHub Runner Scale Set APIs
- EC2 runner provisioning and termination
- Scale-up and scale-down reconciliation
- Scale-set configuration options and their defaults in
docs/configuration.md.
- The
multi-runner-scale-set example and how it relates to the existing multi-runner configuration model.
- Security considerations in
docs/security.md, including:
- IAM permissions and trust boundaries
- SSM-backed configuration and credentials
- Network requirements
- ECS task hardening
- Container image provenance
- Runner ownership and cleanup behavior
- Architecture diagrams and navigation in
docs/index.md, where appropriate.
- The experimental status and current limitations of the scale-set implementation.
- The relationship to the Go scale-set client and API behavior in
actions/scaleset. The service implementation was developed by reverse-engineering the behavior and protocol implemented in that Go code.
Context
Follow-up documentation work for PR #5299, which adds experimental GitHub Actions runner scale-set support.
The current documentation does not fully explain the scale-set architecture, configuration options, security boundaries, or operational behavior.
Scope
Update the documentation to cover:
docs/configuration.md.multi-runner-scale-setexample and how it relates to the existing multi-runner configuration model.docs/security.md, including:docs/index.md, where appropriate.actions/scaleset. The service implementation was developed by reverse-engineering the behavior and protocol implemented in that Go code.