Repository navigation
test(scale-set): run service container smoke test - #5375
Merged
edersonbrilhante merged 15 commits intoSep 18, 2026
Merged
edersonbrilhante merged 15 commits into
edersonbrilhante merged 15 commits into
Conversation
Contributor
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
edersonbrilhante
force-pushed
the
feat-scale-set-typescript-docs-ci
branch
from
September 8, 2026 15:29
54a8eb3 to
1172732
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-image-test
branch
from
September 8, 2026 15:29
4a21477 to
2513185
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-typescript-docs-ci
branch
from
September 8, 2026 20:04
1172732 to
cdca4dc
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-image-test
branch
from
September 8, 2026 20:04
2513185 to
14c5a3a
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-typescript-docs-ci
branch
from
September 8, 2026 20:12
cdca4dc to
d99f1f8
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-image-test
branch
2 times, most recently
from
September 8, 2026 20:48
1dd5c1a to
fe04562
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-typescript-docs-ci
branch
from
September 10, 2026 16:55
4d9bfd0 to
d568ef4
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-image-test
branch
from
September 10, 2026 16:55
fe04562 to
250cf5b
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-typescript-docs-ci
branch
from
September 11, 2026 07:53
d568ef4 to
aca1a4d
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-image-test
branch
from
September 11, 2026 07:53
250cf5b to
e43e206
Compare
edersonbrilhante
removed this pull request from stack #5348
September 15, 2026 09:57
edersonbrilhante
added this pull request to stack #5406
September 15, 2026 09:57
edersonbrilhante
removed this pull request from stack #5406
September 15, 2026 13:54
edersonbrilhante
added this pull request to stack #5432
September 15, 2026 13:55
edersonbrilhante
force-pushed
the
feat-scale-set-typescript-docs-ci
branch
from
September 15, 2026 13:56
aca1a4d to
9f0a3a9
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-image-test
branch
from
September 15, 2026 13:56
e43e206 to
d3572ce
Compare
edersonbrilhante
removed this pull request from stack #5432
September 15, 2026 14:04
edersonbrilhante
added this pull request to stack #5433
September 15, 2026 14:05
edersonbrilhante
force-pushed
the
feat-scale-set-typescript-docs-ci
branch
from
September 15, 2026 14:06
9f0a3a9 to
f0fc8b1
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-image-test
branch
from
September 15, 2026 14:07
d3572ce to
e7904f5
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-typescript-docs-ci
branch
from
September 15, 2026 14:12
f0fc8b1 to
0cda186
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-image-test
branch
from
September 15, 2026 14:12
e7904f5 to
3a541ac
Compare
edersonbrilhante
removed this pull request from stack #5433
September 15, 2026 14:36
edersonbrilhante
added this pull request to stack #5431
September 15, 2026 14:36
edersonbrilhante
force-pushed
the
feat-scale-set-typescript-docs-ci
branch
from
September 15, 2026 14:36
53af972 to
73e4062
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-image-test
branch
from
September 15, 2026 14:36
bbb95ce to
94bb339
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-typescript-docs-ci
branch
from
September 15, 2026 15:08
73e4062 to
f75d003
Compare
Co-authored-by: Guilherme Caulada <guilherme.caulada@gmail.com>
edersonbrilhante
force-pushed
the
feat-scale-set-image-test
branch
from
September 16, 2026 22:32
d84bd7c to
4e96513
Compare
edersonbrilhante
removed this pull request from stack #5431
September 17, 2026 14:28
edersonbrilhante
added this pull request to stack #5437
September 17, 2026 14:38
edersonbrilhante
removed this pull request from stack #5437
September 17, 2026 18:20
edersonbrilhante
added this pull request to stack #5441
September 17, 2026 18:41
edersonbrilhante
removed this pull request from stack #5441
September 17, 2026 19:01
edersonbrilhante
added this pull request to stack #5442
September 17, 2026 19:01
edersonbrilhante
removed this pull request from stack #5442
September 17, 2026 21:40
edersonbrilhante
added this pull request to stack #5443
September 18, 2026 10:18
edersonbrilhante
removed this pull request from stack #5443
September 18, 2026 10:19
edersonbrilhante
added a commit
that referenced
this pull request
Sep 21, 2026
## Description Adds the documentation, CI, release, and integration-test support needed to validate and publish the GitHub Actions scale-set service introduced by #5300. This PR includes: - Dependabot coverage and grouping for GitHub Actions, Lambda dependencies, the scale-set service container, MiniStack, and documentation dependencies. - Lambda CI coverage for formatting, linting, tests, distribution builds, multi-architecture scale-set container builds, and an isolated container smoke test. The smoke test runs the image with a read-only filesystem, dropped capabilities, no-new-privileges, and no network access, then validates the controller health response. - A MiniStack ECS/MockServer integration test that builds and pushes the scale-set image to the local registry, applies the `multi-runner-scale-set` example, validates the rendered SSM configuration and ECS task definition, exercises GitHub App and scale-set protocol requests, verifies runner launch and registration, changes the minimum capacity to zero, verifies scale-down and termination, and cleans up the deployment. - Pinned MockServer expectations and MiniStack fixtures for installation-token exchange, runner registration, scale-set discovery and label updates, JIT configuration generation, message-session creation, polling, and cleanup. - Release workflow support for publishing the multi-architecture scale-set service image to GHCR with an SBOM, build provenance, and registry attestation. Release notes now include the immutable image digest and attestation information alongside Lambda artifact attestations. - Security documentation describing the scale-set image provenance and the `gh attestation verify` command for production image verification. ## Test Plan - Lambda CI runs the repository format, lint, test, and build checks and builds the scale-set image for `linux/amd64` and `linux/arm64`. - The container smoke test validates the hardened image independently of AWS or GitHub. - The MiniStack workflow runs the scale-set ECS/MockServer smoke test with pinned MiniStack and MockServer versions. - `git diff --check` and the changed-file scope were verified for this follow-up branch. ## Related Issues - Follow-up to #5300. - Exercises the Terraform scale-set deployment from #5299. - Includes the scale-set service smoke-test work from #5375. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Guilherme Caulada <guilherme.caulada@gmail.com>
edersonbrilhante
added a commit
that referenced
this pull request
Sep 25, 2026
## Description Consolidates the complete experimental GitHub Actions runner scale-set stack into one PR. It provides the Terraform orchestration, the ECS controller that consumes it, the EC2 compute-provider implementation, the example deployment, and the validation and delivery workflows needed to operate the stack. ### Status and implementation basis - This stack is experimental and its interfaces and behavior may evolve as the scale-set integration matures. - The scale-set service was written based on reverse-engineering the behavior and protocol implemented by the Go code in [`actions/scaleset`](https://github.com/actions/scaleset), which provides the GitHub Actions Runner Scale Set API client and message-session primitives. - Additional user-facing and operational documentation can be added in a follow-up PR. This PR therefore focuses on the implementation, integration coverage, and delivery plumbing; documentation-only jobs are not required to gate this PR. ### Terraform and AWS orchestration - Adds the standalone `modules/orchestration-providers/scale-set` module, which deploys one hardened ECS Fargate controller service per resolved controller group, with private networking, security groups, CloudWatch logging, health checks, deployment rollback, and task-definition safeguards. - Routes scale-set lanes through the provider-aware multi-runner and runner-config composition, with plan-known grouping by compute provider, runner configuration, or explicit membership. - Delivers versioned non-secret reconciler configuration through SSM Parameter Store while keeping GitHub App credentials as SSM references and restricting task- and compute-role permissions to the configured resources. - Adds validation for GitHub scope and scale-set ownership, grouping coverage, plan-time inputs, provider contracts, configuration and task-definition limits, reserved environment variables, wildcard IAM actions, and AWS inline-policy quotas. - Defines the compute-provider capability boundary and implements the EC2 adapter for scale-up, tagging, termination, JIT configuration storage, AMI access, owned-runner discovery, and scale-down reconciliation. ### Scale-set controller and runtime - Adds the reusable GitHub Actions scale-set client for GitHub.com, GHES, and data-residency endpoints, including GitHub App authentication, runner-group and scale-set discovery, JIT configuration, runner removal, and message-session handling. - Adds the long-running ECS controller service with SSM-backed configuration loading, independent reconcilers, liveness/readiness endpoints, bounded shutdown, and session recovery. - Reconciles EC2 capacity from assigned jobs, preserves busy or unknown runners during scale-down, tracks provider-owned instances with tags, and supports task-role or assumed-role credentials. - Keeps sensitive tokens, message bodies, and JIT configurations out of manifests and logs; TLS verification changes are scoped to the relevant client. ### Example, CI, and integration coverage - Adds the `examples/multi-runner-scale-set` deployment, provider locks, outputs, documentation, and the required multi-runner wiring. - Adds Dependabot and CI coverage for formatting, linting, Terraform/OpenTofu tests, TypeScript tests and builds, multi-architecture container builds, and release publication with SBOM, provenance, and registry attestations. - Adds a hardened scale-set container smoke test using a read-only filesystem, dropped capabilities, `no-new-privileges`, and no network access. - Adds MiniStack ECS/MockServer lifecycle coverage for image build and push, controller startup, GitHub App and scale-set protocol requests, runner registration, scale-up, scale-down, EC2 termination, and cleanup. - The Terraform module adopts scale sets that already exist in GitHub by name; it does not create or delete GitHub scale-set resources. ### Merged stack contributions This PR now contains the following merged scale-set PRs: - [#5350](#5350) — wire scale-set orchestration through the provider-aware runner configuration. - [#5405](#5405) — restore the multi-runner scale-set example and its generated/provider metadata. This replaces the earlier [#5378](#5378) example PR. - [#5300](#5300) — add the ECS scale-set controller, client, and EC2 provider runtime. - [#5347](#5347) — add documentation, CI, release, and MiniStack integration support. - [#5375](#5375) — add the scale-set service-container and ECS/MockServer lifecycle smoke coverage, included through #5347. ## Test Plan - Added and updated focused Terraform/OpenTofu tests for the scale-set module, computed inputs, grouping, ownership validation, configuration delivery, IAM policy construction, quota checks, and configuration resolution. - Added TypeScript unit tests covering the scale-set client, HTTP and message-session behavior, service configuration and credentials, controller lifecycle and health, and EC2 provider inventory and reconciliation. - Terraform/OpenTofu formatting, validation, current-interface documentation generation, `tofu test`, TypeScript type-check/build/format/lint/test targets, container smoke tests, and MiniStack lifecycle workflows cover the affected paths. - Broader user-facing and operational documentation is intentionally deferred to a separate PR, so documentation-only jobs do not need to be required for this PR. - `git diff --check` and the repository CI workflows were run for the combined stack. ## Related Issues - Builds on the multi-runner v2 interface from [#5367](#5367). - The scale-set service implementation is informed by [`actions/scaleset`](https://github.com/actions/scaleset). - This PR is the Terraform and deployment stack consumed by the scale-set controller and service changes listed above. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Guilherme Caulada <guilherme.caulada@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Add the scale-set service-container smoke test and the ECS/MockServer scale-set lifecycle test on top of the scale-set Terraform wiring.
lambdas/services/scale-set/Dockerfile, push it to a MiniStack ECR repository, and allow the MiniStack account to pull it.no-new-privileges.minRunners = 1, verify MiniStack creates and registers the EC2 runner, then register a new ECS task definition withminRunners = 0and verify the controller removes the mocked GitHub runner and terminates the EC2 instance.The workflow uses MiniStack 1.5.12 and a pinned MockServer image. The scale-set lifecycle integration remains in this PR; PR #5416 provides only the reusable example-fixture support.
Test Plan
minRunners = 0, EC2 runner termination, MockServer session cleanup, and Terraform destroy.sh -n tests/ministack/run-scale-set-integration.shshellcheck -S warning tests/ministack/run-scale-set-integration.shpython3 -m json.tool mockserver/initializerJson.jsonterraform fmt -check examples/multi-runner-scale-set/main.tf examples/multi-runner-scale-set/variables.tfgit diff --checkRelated Issues
Depends on #5347. The Terraform wiring is provided by the scale-set stack beginning at #5350; the example is restored in #5405.