Skip to content

feat(scale-set): add scale set orchestration in Terraform - #5299

Merged
edersonbrilhante merged 37 commits into
mainfrom
feat-scale-set-terraform
Sep 25, 2026
Merged

edersonbrilhante merged 37 commits into
mainfrom
feat-scale-set-terraform

Conversation

@edersonbrilhante

@edersonbrilhante edersonbrilhante commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Description

Consolidates the complete experimental GitHub Actions runner scale-set stack into one PR. It provides the Terraform orchestration, the ECS controller that consumes it, the EC2 compute-provider implementation, the example deployment, and the validation and delivery workflows needed to operate the stack.

Status and implementation basis

  • This stack is experimental and its interfaces and behavior may evolve as the scale-set integration matures.
  • The scale-set service was written based on reverse-engineering the behavior and protocol implemented by the Go code in actions/scaleset, which provides the GitHub Actions Runner Scale Set API client and message-session primitives.
  • Additional user-facing and operational documentation can be added in a follow-up PR. This PR therefore focuses on the implementation, integration coverage, and delivery plumbing; documentation-only jobs are not required to gate this PR.

Terraform and AWS orchestration

  • Adds the standalone modules/orchestration-providers/scale-set module, which deploys one hardened ECS Fargate controller service per resolved controller group, with private networking, security groups, CloudWatch logging, health checks, deployment rollback, and task-definition safeguards.
  • Routes scale-set lanes through the provider-aware multi-runner and runner-config composition, with plan-known grouping by compute provider, runner configuration, or explicit membership.
  • Delivers versioned non-secret reconciler configuration through SSM Parameter Store while keeping GitHub App credentials as SSM references and restricting task- and compute-role permissions to the configured resources.
  • Adds validation for GitHub scope and scale-set ownership, grouping coverage, plan-time inputs, provider contracts, configuration and task-definition limits, reserved environment variables, wildcard IAM actions, and AWS inline-policy quotas.
  • Defines the compute-provider capability boundary and implements the EC2 adapter for scale-up, tagging, termination, JIT configuration storage, AMI access, owned-runner discovery, and scale-down reconciliation.

Scale-set controller and runtime

  • Adds the reusable GitHub Actions scale-set client for GitHub.com, GHES, and data-residency endpoints, including GitHub App authentication, runner-group and scale-set discovery, JIT configuration, runner removal, and message-session handling.
  • Adds the long-running ECS controller service with SSM-backed configuration loading, independent reconcilers, liveness/readiness endpoints, bounded shutdown, and session recovery.
  • Reconciles EC2 capacity from assigned jobs, preserves busy or unknown runners during scale-down, tracks provider-owned instances with tags, and supports task-role or assumed-role credentials.
  • Keeps sensitive tokens, message bodies, and JIT configurations out of manifests and logs; TLS verification changes are scoped to the relevant client.

Example, CI, and integration coverage

  • Adds the examples/multi-runner-scale-set deployment, provider locks, outputs, documentation, and the required multi-runner wiring.
  • Adds Dependabot and CI coverage for formatting, linting, Terraform/OpenTofu tests, TypeScript tests and builds, multi-architecture container builds, and release publication with SBOM, provenance, and registry attestations.
  • Adds a hardened scale-set container smoke test using a read-only filesystem, dropped capabilities, no-new-privileges, and no network access.
  • Adds MiniStack ECS/MockServer lifecycle coverage for image build and push, controller startup, GitHub App and scale-set protocol requests, runner registration, scale-up, scale-down, EC2 termination, and cleanup.
  • The Terraform module adopts scale sets that already exist in GitHub by name; it does not create or delete GitHub scale-set resources.

Merged stack contributions

This PR now contains the following merged scale-set PRs:

  • #5350 — wire scale-set orchestration through the provider-aware runner configuration.
  • #5405 — restore the multi-runner scale-set example and its generated/provider metadata. This replaces the earlier #5378 example PR.
  • #5300 — add the ECS scale-set controller, client, and EC2 provider runtime.
  • #5347 — add documentation, CI, release, and MiniStack integration support.
  • #5375 — add the scale-set service-container and ECS/MockServer lifecycle smoke coverage, included through chore(scale-set): docs and workflows changes #5347.

Test Plan

  • Added and updated focused Terraform/OpenTofu tests for the scale-set module, computed inputs, grouping, ownership validation, configuration delivery, IAM policy construction, quota checks, and configuration resolution.
  • Added TypeScript unit tests covering the scale-set client, HTTP and message-session behavior, service configuration and credentials, controller lifecycle and health, and EC2 provider inventory and reconciliation.
  • Terraform/OpenTofu formatting, validation, current-interface documentation generation, tofu test, TypeScript type-check/build/format/lint/test targets, container smoke tests, and MiniStack lifecycle workflows cover the affected paths.
  • Broader user-facing and operational documentation is intentionally deferred to a separate PR, so documentation-only jobs do not need to be required for this PR.
  • git diff --check and the repository CI workflows were run for the combined stack.

Related Issues

  • Builds on the multi-runner v2 interface from #5367.
  • The scale-set service implementation is informed by actions/scaleset.
  • This PR is the Terraform and deployment stack consumed by the scale-set controller and service changes listed above.

@edersonbrilhante
edersonbrilhante requested review from a team as code owners August 26, 2026 10:44
@github-actions

github-actions Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 3 package(s) with unknown licenses.
  • ⚠️ 1 packages with OpenSSF Scorecard issues.
See the Details below.

License Issues

lambdas/services/scale-set/package.json

PackageVersionLicenseIssue Type
@aws-github-runner/aws-ssm-utilNullUnknown License
@aws-github-runner/compute-providersNullUnknown License
@aws-github-runner/github-actions-scale-setNullUnknown License

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
npm/@aws-sdk/client-ssm ^3.1009.0 UnknownUnknown
npm/@types/node ^22.19.3 UnknownUnknown
npm/typescript ^5.9.3 UnknownUnknown
npm/@aws-sdk/core 3.977.9 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/credential-provider-cognito-identity 3.972.69 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/credential-provider-env 3.972.70 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/credential-provider-http 3.972.72 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/credential-provider-ini 3.973.15 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/credential-provider-login 3.972.77 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/credential-provider-node 3.972.82 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/credential-provider-process 3.972.70 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/credential-provider-sso 3.973.14 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/credential-provider-web-identity 3.972.76 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/credential-providers 3.1127.0 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/nested-clients 3.997.44 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/signature-v4-multi-region 3.996.46 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/token-providers 3.1116.0 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/types 3.974.5 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws-sdk/xml-builder 3.972.40 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 5detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing🟢 10project is fuzzed
npm/@aws/lambda-invoke-store 0.3.0 UnknownUnknown
npm/@oxc-project/types 0.148.0 UnknownUnknown
npm/@rolldown/binding-android-arm-eabi 1.2.7 UnknownUnknown
npm/@rolldown/binding-android-arm64 1.2.7 UnknownUnknown
npm/@rolldown/binding-darwin-arm64 1.2.7 UnknownUnknown
npm/@rolldown/binding-darwin-x64 1.2.7 UnknownUnknown
npm/@rolldown/binding-freebsd-x64 1.2.7 UnknownUnknown
npm/@rolldown/binding-linux-arm-gnueabihf 1.2.7 UnknownUnknown
npm/@rolldown/binding-linux-arm64-gnu 1.2.7 UnknownUnknown
npm/@rolldown/binding-linux-arm64-musl 1.2.7 UnknownUnknown
npm/@rolldown/binding-linux-ppc64-gnu 1.2.7 UnknownUnknown
npm/@rolldown/binding-linux-s390x-gnu 1.2.7 UnknownUnknown
npm/@rolldown/binding-linux-x64-gnu 1.2.7 UnknownUnknown
npm/@rolldown/binding-linux-x64-musl 1.2.7 UnknownUnknown
npm/@rolldown/binding-openharmony-arm64 1.2.7 UnknownUnknown
npm/@rolldown/binding-win32-arm64-msvc 1.2.7 UnknownUnknown
npm/@rolldown/binding-win32-x64-msvc 1.2.7 UnknownUnknown
npm/@smithy/core 3.33.3 UnknownUnknown
npm/@smithy/credential-provider-imds 4.5.2 UnknownUnknown
npm/@smithy/fetch-http-handler 5.8.0 UnknownUnknown
npm/@smithy/node-http-handler 4.12.1 UnknownUnknown
npm/@smithy/signature-v4 5.7.3 UnknownUnknown
npm/@smithy/types 4.18.0 UnknownUnknown
npm/@vitest/coverage-v8 4.1.11 UnknownUnknown
npm/ast-v8-to-istanbul 1.0.6 UnknownUnknown
npm/js-tokens 10.0.0 ⚠️ 2.9
Details
CheckScoreReason
Code-Review⚠️ 0Found 2/23 approved changesets -- score normalized to 0
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 2dependency not pinned by hash detected -- score normalized to 2
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/magicast 0.5.4 UnknownUnknown
npm/rolldown 1.2.7 UnknownUnknown
npm/undici 6.28.0 🟢 8.1
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Dependency-Update-Tool🟢 10update tool detected
Security-Policy🟢 10security policy file detected
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 8binaries present in source code
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Vulnerabilities🟢 64 existing vulnerabilities detected
SAST🟢 9SAST tool detected but not run on all commits
Packaging🟢 10packaging workflow detected
Fuzzing🟢 10project is fuzzed
Signed-Releases⚠️ -1no releases found
CI-Tests🟢 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 64 contributing companies or organizations
npm/vite 8.2.2 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 9 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 8Found 20/23 approved changesets -- score normalized to 8
Token-Permissions🟢 7detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts⚠️ 1binaries present in source code
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
SAST🟢 10SAST tool is run on all commits
npm/@aws-github-runner/aws-ssm-util UnknownUnknown
npm/@aws-github-runner/compute-providers UnknownUnknown
npm/@aws-github-runner/github-actions-scale-set UnknownUnknown
npm/@aws-sdk/client-ssm ^3.1009.0 UnknownUnknown
npm/@aws-sdk/credential-providers ^3.1009.0 UnknownUnknown
npm/@octokit/auth-app 8.2.0 🟢 6.8
Details
CheckScoreReason
Maintained🟢 56 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5
Binary-Artifacts🟢 10no binaries found in the repo
Code-Review🟢 10all changesets reviewed
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Security-Policy🟢 9security policy file detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
npm/@octokit/request ^9.2.2 UnknownUnknown
npm/@types/node ^22.19.3 UnknownUnknown
npm/@vercel/ncc 0.38.4 🟢 6.8
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 55 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 5
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Security-Policy🟢 10security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/typescript ^5.9.3 UnknownUnknown
npm/undici ^6.19.2 UnknownUnknown

Scanned Files

  • lambdas/libs/compute-providers/package.json
  • lambdas/libs/github-actions-scale-set/package.json
  • lambdas/services/scale-set/package.json
  • lambdas/yarn.lock

@edersonbrilhante
edersonbrilhante marked this pull request as draft August 26, 2026 13:59
@edersonbrilhante
edersonbrilhante force-pushed the experimental-multi-runner-config-v2-20260805 branch 2 times, most recently from 5eafe5c to 2b6bb21 Compare September 2, 2026 20:18
@edersonbrilhante
edersonbrilhante changed the base branch from experimental-multi-runner-config-v2-20260805 to refactor-runner-config-module September 3, 2026 19:59
@edersonbrilhante
edersonbrilhante force-pushed the refactor-runner-config-module branch 2 times, most recently from c979cbb to 4d9e31c Compare September 3, 2026 20:03
@edersonbrilhante
edersonbrilhante changed the base branch from refactor-runner-config-module to experimental-multi-runner-config-v2-20260805 September 3, 2026 20:05
@edersonbrilhante
edersonbrilhante changed the base branch from experimental-multi-runner-config-v2-20260805 to fix-multi-runner-v2-routing September 3, 2026 20:21
@edersonbrilhante edersonbrilhante changed the title feat(scale-set): add ECS orchestration feat(scale-set): add scale set orchestration in Terraform Sep 3, 2026
@edersonbrilhante
edersonbrilhante force-pushed the feat-scale-set-terraform branch 2 times, most recently from 5ab14e1 to 4375247 Compare September 3, 2026 21:13
@edersonbrilhante
edersonbrilhante force-pushed the fix-multi-runner-v2-routing branch from 00c76ce to 01c4a78 Compare September 3, 2026 21:19
@edersonbrilhante
edersonbrilhante force-pushed the fix-multi-runner-v2-routing branch from 01c4a78 to 5b2fbf4 Compare September 3, 2026 21:40
@edersonbrilhante
edersonbrilhante force-pushed the fix-multi-runner-v2-routing branch from 5b2fbf4 to afc760b Compare September 3, 2026 21:52
@edersonbrilhante
edersonbrilhante changed the base branch from fix-multi-runner-v2-routing to microvm-multi-runner-terraform September 3, 2026 22:03
@edersonbrilhante
edersonbrilhante changed the base branch from microvm-multi-runner-terraform to microvm-multi-runner-integration-split September 3, 2026 22:04
@edersonbrilhante
edersonbrilhante changed the base branch from microvm-multi-runner-integration-split to fix-multi-runner-v2-routing September 3, 2026 22:04
@edersonbrilhante
edersonbrilhante force-pushed the fix-multi-runner-v2-routing branch from afc760b to e17ae16 Compare September 4, 2026 17:59
@edersonbrilhante
edersonbrilhante changed the base branch from fix-multi-runner-v2-routing to remove-v2-legacy-input-requirements September 4, 2026 18:08
@edersonbrilhante
edersonbrilhante changed the base branch from remove-v2-legacy-input-requirements to add-multi-runner-v2-example September 4, 2026 18:10
@edersonbrilhante
edersonbrilhante changed the base branch from add-multi-runner-v2-example to main September 4, 2026 18:12
@edersonbrilhante
edersonbrilhante changed the base branch from main to add-multi-runner-v2-example September 4, 2026 18:12
@edersonbrilhante

Copy link
Copy Markdown
Contributor Author

@npalm Done

@edersonbrilhante

Copy link
Copy Markdown
Contributor Author

@npalm I created the issue for to update the docs in a follow up PR #5470

npalm
npalm previously requested changes Sep 23, 2026

@npalm npalm left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Solid foundation. The security posture stands out: container hardening in task.tf, tag-conditioned EC2 IAM in the compute provider, credential values kept out of Terraform entirely (only SSM parameter names threaded through), and workflow-level supply chain hygiene at release (sbom: true, provenance: mode=max, actions/attest, SHA-pinned actions, harden-runner). Nice work.

One thing to fix before merge

The task role in modules/orchestration-providers/scale-set/iam.tf grants only SSM read actions, but the controller writes discovered IDs back to SSM at credentials.ts:189 (installation ID) and reconciler.ts:261 (runner group ID) through parameterStore.put. First cache write will fail with AccessDenied at runtime. Either add a scoped ssm:PutParameter on those two ARNs or drop the write-back path. Details in the inline comment.

Docs missing from this PR

This change introduces a new orchestration mode, a new deployment shape (ECS Fargate controller alongside the existing Lambdas), a new grouping model, and a new set of experimental variables. The only doc touched is docs/security.md. Please add:

  • docs/index.md and docs/configuration.md: extend the architecture description and the configuration reference to cover the scale-set orchestration provider, the controller group model, and the new experimental variables.
  • docs/multi-runner-v1-to-v2-configuration.md and docs/multi-runner-v1-v2-migration.md: add the scale-set option so v2 adopters can find it and understand when to pick it.
  • A new ADR under docs/adr/ capturing the "adopt existing scale sets by name, do not manage them" contract, alongside docs/adr/002-runner-orchestration-provider-boundary.md.
  • modules/orchestration-providers/scale-set/README.md and variables.tf: make the security trade-off on the default 0.0.0.0/0 egress explicit (GitHub's outbound ranges at https://api.github.com/meta are pinnable), so adopters make the call consciously.

The remaining inline comments are suggestions and small nudges. Happy to iterate on any of them.

Comment thread modules/orchestration-providers/scale-set/iam.tf
Comment thread modules/orchestration-providers/scale-set/locals.tf
Comment thread modules/orchestration-providers/scale-set/iam.tf
Comment thread modules/orchestration-providers/scale-set/variables.tf
Comment thread lambdas/services/scale-set/src/reconciler.ts
Comment thread lambdas/services/scale-set/src/main.ts
Comment thread modules/orchestration-providers/scale-set/variables.tf
Comment thread .github/workflows/lambda.yml Outdated
Comment thread .github/workflows/smoke-tests.yml
@edersonbrilhante

Copy link
Copy Markdown
Contributor Author

@npalm I created an issue to follow up your review.
#5471

This PR is too big after the PRs got merged one after another. If you don't mind approving as compromise, I will handle this fix in a new PR, so the review is easier and cleaner

@edersonbrilhante

Copy link
Copy Markdown
Contributor Author

guicaulada
guicaulada previously approved these changes Sep 24, 2026
Brend-Smits
Brend-Smits previously approved these changes Sep 25, 2026
Brend-Smits
Brend-Smits previously approved these changes Sep 25, 2026
Brend-Smits
Brend-Smits previously approved these changes Sep 25, 2026
Brend-Smits
Brend-Smits previously approved these changes Sep 25, 2026
Brend-Smits
Brend-Smits previously approved these changes Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants