Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
37 commits
Select commit Hold shift + click to select a range
150638c
feat(scale-set): isolate orchestration provider module
edersonbrilhante Sep 17, 2026
c87e2b8
fix(scale-set): validate compute task policy
edersonbrilhante Sep 17, 2026
344736c
docs: auto update terraform docs
github-actions[bot] Sep 17, 2026
0379201
fix(scale-set): use declared task policy for quota validation
edersonbrilhante Sep 17, 2026
98693b4
docs: auto update terraform docs
github-actions[bot] Sep 17, 2026
527dadd
feat(scale-set): wire orchestration through runner config (#5350)
edersonbrilhante Sep 17, 2026
49db3b5
test(examples): add scale-set orchestration example (#5405)
edersonbrilhante Sep 17, 2026
c91d8ca
fix(scale-set): remove invalid policy validation reference
edersonbrilhante Sep 17, 2026
5b52346
ci: fix multi runner scaleset test
edersonbrilhante Sep 17, 2026
0710bc3
docs: auto update terraform docs
github-actions[bot] Sep 17, 2026
ec123d2
fix: fix tests
edersonbrilhante Sep 17, 2026
283484b
docs: auto update terraform docs
github-actions[bot] Sep 17, 2026
99ae1bc
fix: fix validations
edersonbrilhante Sep 17, 2026
4d8cffa
fix(multi-runner): validate scale-set installation inputs
edersonbrilhante Sep 18, 2026
ea91c63
test: fix example and test
edersonbrilhante Sep 18, 2026
3310bd8
test: fix tofu test
edersonbrilhante Sep 18, 2026
4256d6f
test: add fixture to support tofu tests
edersonbrilhante Sep 18, 2026
f0fa1e8
docs: auto update terraform docs
edersonbrilhante Sep 18, 2026
852b92e
feat(scale-set): add service controller (#5300)
edersonbrilhante Sep 21, 2026
1799908
Merge branch 'main' into feat-scale-set-terraform
edersonbrilhante Sep 21, 2026
cf6b86a
docs: auto update terraform docs
github-actions[bot] Sep 21, 2026
c4c7811
Merge remote-tracking branch 'origin/main' into feat-scale-set-terraform
edersonbrilhante Sep 22, 2026
f4c2ce4
docs: auto update terraform docs
github-actions[bot] Sep 22, 2026
fa85df7
fix: fix conflicts
edersonbrilhante Sep 22, 2026
ddda517
fix: fix conflicts
edersonbrilhante Sep 22, 2026
17a07eb
Merge branch 'main' into feat-scale-set-terraform
edersonbrilhante Sep 23, 2026
23c988f
docs: auto update terraform docs
github-actions[bot] Sep 23, 2026
8a9498c
Merge branch 'main' into feat-scale-set-terraform
edersonbrilhante Sep 23, 2026
7a7bc88
docs: auto update terraform docs
github-actions[bot] Sep 23, 2026
87d888a
ci: move script to tests folder
edersonbrilhante Sep 25, 2026
2a3e1f5
Merge branch 'main' into feat-scale-set-terraform
edersonbrilhante Sep 25, 2026
3adfa57
ci: undo change in release pipeline
edersonbrilhante Sep 25, 2026
b4f975c
Merge remote-tracking branch 'origin/feat-scale-set-terraform' into f…
edersonbrilhante Sep 25, 2026
06991f6
ci: undo changes in .github/dependabot.yml
edersonbrilhante Sep 25, 2026
db2c3fb
ci: undo changes in .pre-commit-config.yaml
edersonbrilhante Sep 25, 2026
d33fda4
ci: undo changes in lambda.yml
edersonbrilhante Sep 25, 2026
828b6d9
chore: rename scaleset LICENSE
edersonbrilhante Sep 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .github/workflows/ministack.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@ jobs:
- ephemeral
- multi-runner
- multi-runner-v2
- multi-runner-scale-set
- migration-test
- termination-watcher
services:
Expand Down Expand Up @@ -114,4 +115,4 @@ jobs:
EXAMPLE: ${{ matrix.example }}
IAC_BINARY: ${{ matrix.iac.binary }}
IAC_LOCK_FILE: ${{ matrix.iac.lockfile }}
run: tests/ministack/run-example.sh destroy "$EXAMPLE"
run: tests/ministack/run-example.sh destroy "$EXAMPLE"
75 changes: 75 additions & 0 deletions .github/workflows/smoke-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -83,3 +83,78 @@ jobs:
MINISTACK_GITHUB_MOCK_PORT: "1080"
MINISTACK_GITHUB_MOCK_URL: ${{ steps.mockserver.outputs.url }}
run: sh tests/ministack/run-smoke.sh

scale_set_integration_smoke:
name: Run scale-set ECS smoke test against MiniStack and MockServer
runs-on: ubuntu-latest
timeout-minutes: 30
services:
ministack:
image: ghcr.io/ministackorg/ministack:1.5.12@sha256:41fe1ce2e666c6cc410c6047a9db8bf1df69cd0028ebc0a6c6e5517c3a83d6e0
ports:
- 4566:4566
options: >-
--add-host=host.docker.internal:host-gateway
--volume /var/run/docker.sock:/var/run/docker.sock
env:
MINISTACK_ACCOUNT_ID: "000000000000"
MINISTACK_REGION: eu-west-1
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: lambdas/.nvmrc
package-manager-cache: false

- name: Setup Terraform
uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1
with:
terraform_version: latest
terraform_wrapper: false

- name: Install Lambda dependencies
working-directory: lambdas
run: yarn install --frozen-lockfile

- name: Build smoke-test Lambda distributions
working-directory: lambdas
run: |
yarn workspace @aws-github-runner/webhook dist
yarn workspace @aws-github-runner/control-plane dist

- name: Start MockServer
id: mockserver
uses: mock-server/setup-mockserver@24612c2ccef1f83d587f331ed77cc5cef441e0b1 # v1.0.0
with:
version: '7.6.0@sha256:80b3b1a26f3553d0c81a3f3896b5b7274c17b2a2e52f0fd2b28e246bc9efa290'
port: '1080'
startup-timeout: '60'

- name: Connect MockServer to MiniStack network
shell: bash
run: |
set -euo pipefail
ministack_container="$(docker ps --format '{{.ID}} {{.Image}}' | awk '$2 ~ /ministack/ {print $1; exit}')"
network="$(docker inspect --format '{{range $name, $_ := .NetworkSettings.Networks}}{{println $name}}{{end}}' "$ministack_container" | sed -n '1p')"
docker network connect --alias mockserver "$network" mockserver

- name: Mark repository as safe
shell: sh
run: git config --global --add safe.directory "$GITHUB_WORKSPACE"

- name: Run scale-set ECS/MockServer smoke test
env:
MINISTACK_GITHUB_MOCK_HOST: mockserver
MINISTACK_GITHUB_MOCK_PORT: "1080"
MINISTACK_GITHUB_MOCK_URL: ${{ steps.mockserver.outputs.url }}
run: sh tests/ministack/run-scale-set-integration.sh
81 changes: 70 additions & 11 deletions .github/workflows/terraform.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
name: "Terraform checks"

on:
push:
branches:
Expand All @@ -23,6 +24,7 @@ env:
modules/download-lambda
modules/lambda
modules/multi-runner
modules/orchestration-providers/scale-set
modules/orchestration-providers/webhook
modules/orchestration-providers/webhook/job-retry
modules/orchestration-providers/webhook/pool
Expand All @@ -49,15 +51,19 @@ env:
termination-watcher
multi-runner
multi-runner-v2
multi-runner-scale-set
external-managed-ssm-secrets
TEST_MODULES: |
modules/runners
modules/multi-runner
modules/orchestration-providers/scale-set

jobs:
verify_modules:
name: Verify modules (${{ matrix.iac.name }} ${{ matrix.iac.version }})
strategy:
fail-fast: false
fail-fast: true
max-parallel: 1
matrix:
iac:
- name: terraform
Expand All @@ -72,7 +78,9 @@ jobs:
- name: tofu-latest
version: latest
command: tofu

runs-on: ubuntu-latest

steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
Expand All @@ -97,7 +105,7 @@ jobs:
mkdir -p "$HOME/.terraform.d/plugin"
echo "TF_PLUGIN_CACHE_DIR=$HOME/.terraform.d/plugin" >> "$GITHUB_ENV"

- name: "Fake zip files" # Validate will fail if it cannot find the zip files
- name: Fake zip files
run: |
touch lambdas/functions/webhook/webhook.zip
touch lambdas/functions/control-plane/runners.zip
Expand Down Expand Up @@ -125,7 +133,10 @@ jobs:
run: |
printf '%s\n' "${MODULES}" | while IFS= read -r module; do
[ -z "${module}" ] && continue

echo "::group::Running $IAC_COMMAND init for module: ${module}"
$IAC_COMMAND -chdir="${module}" init -get -backend=false -input=false
echo "::endgroup::"
done

- name: Check ${{ matrix.iac.name }} formatting
Expand All @@ -134,7 +145,10 @@ jobs:
run: |
printf '%s\n' "${MODULES}" | while IFS= read -r module; do
[ -z "${module}" ] && continue

echo "::group::Checking $IAC_COMMAND formatting for module: ${module}"
$IAC_COMMAND -chdir="${module}" fmt -recursive -check=true -write=false
echo "::endgroup::"
done
continue-on-error: ${{ matrix.iac.version == 'latest' }}

Expand All @@ -144,7 +158,10 @@ jobs:
run: |
printf '%s\n' "${MODULES}" | while IFS= read -r module; do
[ -z "${module}" ] && continue

echo "::group::Validating module: ${module}"
$IAC_COMMAND -chdir="${module}" validate
echo "::endgroup::"
done

- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
Expand All @@ -161,15 +178,23 @@ jobs:
- name: Run TFLint
run: |
tflint --init -c ${GITHUB_WORKSPACE}/.tflint.hcl

printf '%s\n' "${MODULES}" | while IFS= read -r module; do
[ -z "${module}" ] && continue
tflint -f compact -c ${GITHUB_WORKSPACE}/.tflint.hcl --var-file ${GITHUB_WORKSPACE}/.github/lint/tflint.tfvars --chdir "${module}"

echo "::group::Running TFLint for module: ${module}"
tflint -f compact \
-c ${GITHUB_WORKSPACE}/.tflint.hcl \
--var-file ${GITHUB_WORKSPACE}/.github/lint/tflint.tfvars \
--chdir "${module}"
echo "::endgroup::"
done

verify_examples:
name: Verify examples (${{ matrix.iac.name }} ${{ matrix.iac.version }})
strategy:
fail-fast: false
fail-fast: true
max-parallel: 1
matrix:
iac:
- name: terraform
Expand All @@ -188,7 +213,9 @@ jobs:
version: latest
command: tofu
lockfile: .terraform.lock.hcl.tofu

runs-on: ubuntu-latest

steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
Expand Down Expand Up @@ -234,7 +261,11 @@ jobs:
run: |
printf '%s\n' "${EXAMPLES}" | while IFS= read -r example; do
[ -z "${example}" ] && continue
cp "examples/${example}/${IAC_LOCK_FILE}" "examples/${example}/.terraform.lock.hcl"

echo "::group::Selecting lockfile for example: ${example}"
cp "examples/${example}/${IAC_LOCK_FILE}" \
"examples/${example}/.terraform.lock.hcl"
echo "::endgroup::"
done

- name: ${{ matrix.iac.name }} init
Expand All @@ -243,7 +274,11 @@ jobs:
run: |
printf '%s\n' "${EXAMPLES}" | while IFS= read -r example; do
[ -z "${example}" ] && continue
$IAC_COMMAND -chdir="examples/${example}" init -get -backend=false -input=false -lockfile=readonly

echo "::group::Running $IAC_COMMAND init for example: ${example}"
$IAC_COMMAND -chdir="examples/${example}" init \
-get -backend=false -input=false -lockfile=readonly
echo "::endgroup::"
done

- name: Check ${{ matrix.iac.name }} formatting
Expand All @@ -252,7 +287,11 @@ jobs:
run: |
printf '%s\n' "${EXAMPLES}" | while IFS= read -r example; do
[ -z "${example}" ] && continue
$IAC_COMMAND -chdir="examples/${example}" fmt -recursive -check=true -write=false

echo "::group::Checking $IAC_COMMAND formatting for example: ${example}"
$IAC_COMMAND -chdir="examples/${example}" fmt \
-recursive -check=true -write=false
echo "::endgroup::"
done
continue-on-error: ${{ matrix.iac.version == 'latest' }}

Expand All @@ -262,7 +301,10 @@ jobs:
run: |
printf '%s\n' "${EXAMPLES}" | while IFS= read -r example; do
[ -z "${example}" ] && continue

echo "::group::Validating example: ${example}"
$IAC_COMMAND -chdir="examples/${example}" validate
echo "::endgroup::"
done

- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
Expand All @@ -279,15 +321,23 @@ jobs:
- name: Run TFLint
run: |
tflint --init -c ${GITHUB_WORKSPACE}/.tflint.hcl

printf '%s\n' "${EXAMPLES}" | while IFS= read -r example; do
[ -z "${example}" ] && continue
tflint -f compact -c ${GITHUB_WORKSPACE}/.tflint.hcl --var-file ${GITHUB_WORKSPACE}/.github/lint/tflint.tfvars --chdir "examples/${example}"

echo "::group::Running TFLint for example: ${example}"
tflint -f compact \
-c ${GITHUB_WORKSPACE}/.tflint.hcl \
--var-file ${GITHUB_WORKSPACE}/.github/lint/tflint.tfvars \
--chdir "examples/${example}"
echo "::endgroup::"
done

terraform_test:
name: ${{ matrix.iac.name }} test
strategy:
fail-fast: false
fail-fast: true
max-parallel: 1
matrix:
iac:
- name: terraform
Expand All @@ -296,7 +346,9 @@ jobs:
- name: tofu
version: latest
command: tofu

runs-on: ubuntu-latest

steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
Expand Down Expand Up @@ -341,7 +393,11 @@ jobs:
run: |
printf '%s\n' "${TEST_MODULES}" | while IFS= read -r module; do
[ -z "${module}" ] && continue
$IAC_COMMAND -chdir="${module}" init -backend=false -input=false

echo "::group::Running $IAC_COMMAND init for test module: ${module}"
$IAC_COMMAND -chdir="${module}" init \
-backend=false -input=false
echo "::endgroup::"
done

- name: ${{ matrix.iac.name }} test
Expand All @@ -350,5 +406,8 @@ jobs:
run: |
printf '%s\n' "${TEST_MODULES}" | while IFS= read -r module; do
[ -z "${module}" ] && continue
$IAC_COMMAND -chdir="${module}" test -test-directory=tests

echo "::group::Running $IAC_COMMAND test for module: ${module}"
$IAC_COMMAND -chdir="${module}" test -test-directory=tests -compact-warnings
echo "::endgroup::"
done
10 changes: 9 additions & 1 deletion docs/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,14 @@ The examples are using standard AMI's for different operating systems. Instances

## Attestation

The module is released using GitHub actions and the lambda artifacts are attached to the release as attachment. During the release attestations are created. The attestations are created by the release pipeline. You find a link to the attestation in the GitHub release. The attestation only provides provenance information about the release. The attestations are not a security guarantee. We recommend you to verify the attestation after downloading the lambda artifacts.
The module is released using GitHub Actions and the Lambda artifacts are attached to the release. The release pipeline creates provenance attestations for those artifacts. You can find a link to the attestation in the GitHub release. The attestation only provides provenance information about the release; it is not a security guarantee. We recommend verifying the attestation after downloading the Lambda artifacts.

Releases also publish the multi-architecture scale-set service image to the GitHub Container Registry with an SBOM, build provenance, and a registry attestation. The convenience image default follows the latest module release. Production deployments should override it with the immutable image digest printed in the release notes, then verify that image with:

```bash
gh attestation verify \
oci://ghcr.io/github-aws-runners/terraform-aws-github-runner-scale-set-service@sha256:<digest> \
--repo github-aws-runners/terraform-aws-github-runner
```

--8<-- "SECURITY.md:mkdocsrunners"

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading