Repository navigation
feat(examples): demonstrate scale-set orchestration - #5378
Merged
edersonbrilhante merged 21 commits intoSep 10, 2026
Merged
Conversation
Contributor
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
from
September 4, 2026 21:31
cfe6d39 to
9be7d90
Compare
edersonbrilhante
marked this pull request as draft
September 4, 2026 21:37
edersonbrilhante
marked this pull request as ready for review
September 4, 2026 21:37
edersonbrilhante
marked this pull request as draft
September 4, 2026 21:38
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
from
September 8, 2026 11:15
cedaa9d to
952942c
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
from
September 8, 2026 11:25
313bd7c to
88407ed
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
from
September 8, 2026 15:41
88407ed to
8db4ae2
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
from
September 8, 2026 19:48
40a85f4 to
e814cdc
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
3 times, most recently
from
September 9, 2026 09:57
ca4c798 to
c91596b
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
2 times, most recently
from
September 9, 2026 11:00
5c5c18a to
c39e9a3
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
from
September 9, 2026 11:17
c39e9a3 to
cc39dcb
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
from
September 9, 2026 13:18
40bf812 to
b9f7788
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
from
September 10, 2026 17:56
5b32e39 to
0d54efd
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-example
branch
from
September 10, 2026 18:08
0d54efd to
187bb1e
Compare
This was referenced Sep 10, 2026
edersonbrilhante
added a commit
that referenced
this pull request
Sep 17, 2026
## Description Restore the multi-runner scale-set orchestration example removed by revert PR #5403, replacing merged PR #5378. The example provides the Terraform configuration, provider locks, outputs, and documentation needed to deploy an ECS scale-set controller with the EC2 runner compute provider. It is intentionally limited to the example and its generated/provider metadata; the reusable MiniStack fixture support and ECS/MockServer lifecycle smoke test are provided by the follow-up PRs. ## Test Plan - Terraform formatting passed through the repository hooks. - Merge-conflict checks passed. - Parent-branch Terraform checks passed after the idle-configuration correction. - No live AWS deployment was performed for this example-only PR; CI validation remains the authoritative deployment check. ## Related Issues Depends on #5350. Replaces #5378. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
edersonbrilhante
added a commit
that referenced
this pull request
Sep 25, 2026
## Description Consolidates the complete experimental GitHub Actions runner scale-set stack into one PR. It provides the Terraform orchestration, the ECS controller that consumes it, the EC2 compute-provider implementation, the example deployment, and the validation and delivery workflows needed to operate the stack. ### Status and implementation basis - This stack is experimental and its interfaces and behavior may evolve as the scale-set integration matures. - The scale-set service was written based on reverse-engineering the behavior and protocol implemented by the Go code in [`actions/scaleset`](https://github.com/actions/scaleset), which provides the GitHub Actions Runner Scale Set API client and message-session primitives. - Additional user-facing and operational documentation can be added in a follow-up PR. This PR therefore focuses on the implementation, integration coverage, and delivery plumbing; documentation-only jobs are not required to gate this PR. ### Terraform and AWS orchestration - Adds the standalone `modules/orchestration-providers/scale-set` module, which deploys one hardened ECS Fargate controller service per resolved controller group, with private networking, security groups, CloudWatch logging, health checks, deployment rollback, and task-definition safeguards. - Routes scale-set lanes through the provider-aware multi-runner and runner-config composition, with plan-known grouping by compute provider, runner configuration, or explicit membership. - Delivers versioned non-secret reconciler configuration through SSM Parameter Store while keeping GitHub App credentials as SSM references and restricting task- and compute-role permissions to the configured resources. - Adds validation for GitHub scope and scale-set ownership, grouping coverage, plan-time inputs, provider contracts, configuration and task-definition limits, reserved environment variables, wildcard IAM actions, and AWS inline-policy quotas. - Defines the compute-provider capability boundary and implements the EC2 adapter for scale-up, tagging, termination, JIT configuration storage, AMI access, owned-runner discovery, and scale-down reconciliation. ### Scale-set controller and runtime - Adds the reusable GitHub Actions scale-set client for GitHub.com, GHES, and data-residency endpoints, including GitHub App authentication, runner-group and scale-set discovery, JIT configuration, runner removal, and message-session handling. - Adds the long-running ECS controller service with SSM-backed configuration loading, independent reconcilers, liveness/readiness endpoints, bounded shutdown, and session recovery. - Reconciles EC2 capacity from assigned jobs, preserves busy or unknown runners during scale-down, tracks provider-owned instances with tags, and supports task-role or assumed-role credentials. - Keeps sensitive tokens, message bodies, and JIT configurations out of manifests and logs; TLS verification changes are scoped to the relevant client. ### Example, CI, and integration coverage - Adds the `examples/multi-runner-scale-set` deployment, provider locks, outputs, documentation, and the required multi-runner wiring. - Adds Dependabot and CI coverage for formatting, linting, Terraform/OpenTofu tests, TypeScript tests and builds, multi-architecture container builds, and release publication with SBOM, provenance, and registry attestations. - Adds a hardened scale-set container smoke test using a read-only filesystem, dropped capabilities, `no-new-privileges`, and no network access. - Adds MiniStack ECS/MockServer lifecycle coverage for image build and push, controller startup, GitHub App and scale-set protocol requests, runner registration, scale-up, scale-down, EC2 termination, and cleanup. - The Terraform module adopts scale sets that already exist in GitHub by name; it does not create or delete GitHub scale-set resources. ### Merged stack contributions This PR now contains the following merged scale-set PRs: - [#5350](#5350) — wire scale-set orchestration through the provider-aware runner configuration. - [#5405](#5405) — restore the multi-runner scale-set example and its generated/provider metadata. This replaces the earlier [#5378](#5378) example PR. - [#5300](#5300) — add the ECS scale-set controller, client, and EC2 provider runtime. - [#5347](#5347) — add documentation, CI, release, and MiniStack integration support. - [#5375](#5375) — add the scale-set service-container and ECS/MockServer lifecycle smoke coverage, included through #5347. ## Test Plan - Added and updated focused Terraform/OpenTofu tests for the scale-set module, computed inputs, grouping, ownership validation, configuration delivery, IAM policy construction, quota checks, and configuration resolution. - Added TypeScript unit tests covering the scale-set client, HTTP and message-session behavior, service configuration and credentials, controller lifecycle and health, and EC2 provider inventory and reconciliation. - Terraform/OpenTofu formatting, validation, current-interface documentation generation, `tofu test`, TypeScript type-check/build/format/lint/test targets, container smoke tests, and MiniStack lifecycle workflows cover the affected paths. - Broader user-facing and operational documentation is intentionally deferred to a separate PR, so documentation-only jobs do not need to be required for this PR. - `git diff --check` and the repository CI workflows were run for the combined stack. ## Related Issues - Builds on the multi-runner v2 interface from [#5367](#5367). - The scale-set service implementation is informed by [`actions/scaleset`](https://github.com/actions/scaleset). - This PR is the Terraform and deployment stack consumed by the scale-set controller and service changes listed above. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Guilherme Caulada <guilherme.caulada@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds the
multi-runner-scale-setexample for the experimental v2 interface.orchestration_provider.scale_setand the SSM-backed GitHub installation reference.Test Plan
terraform fmt -check -recursiveterraform init -backend=falseterraform validateRelated Issues
Depends on #5350.