Skip to content

feat(examples): demonstrate scale-set orchestration - #5378

Merged
edersonbrilhante merged 21 commits into
feat-scale-set-terraform-wiringfrom
feat-scale-set-example
Sep 10, 2026
Merged

edersonbrilhante merged 21 commits into
feat-scale-set-terraform-wiringfrom
feat-scale-set-example

Conversation

@edersonbrilhante

@edersonbrilhante edersonbrilhante commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Description

Adds the multi-runner-scale-set example for the experimental v2 interface.

  • Demonstrates webhook lanes alongside a GitHub Actions scale-set lane.
  • Uses shared global networking, Lambda, and runner-binary defaults with per-lane matcher, lifecycle, AMI, and instance settings.
  • Configures orchestration_provider.scale_set and the SSM-backed GitHub installation reference.
  • Adds the example to the Terraform verification workflow and documentation.

Test Plan

  • terraform fmt -check -recursive
  • terraform init -backend=false
  • terraform validate
  • Repository Terraform formatting, validation/TFLint, and merge-conflict checks

Related Issues

Depends on #5350.

@edersonbrilhante
edersonbrilhante requested a review from a team as a September 4, 2026 21:26
@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@edersonbrilhante
edersonbrilhante marked this pull request as draft September 4, 2026 21:37
@edersonbrilhante
edersonbrilhante marked this pull request as ready for review September 4, 2026 21:37
@edersonbrilhante
edersonbrilhante marked this pull request as draft September 4, 2026 21:38
@edersonbrilhante
edersonbrilhante force-pushed the feat-scale-set-example branch 3 times, most recently from ca4c798 to c91596b Compare September 9, 2026 09:57
@edersonbrilhante
edersonbrilhante force-pushed the feat-scale-set-example branch 2 times, most recently from 5c5c18a to c39e9a3 Compare September 9, 2026 11:00
@edersonbrilhante
edersonbrilhante merged commit 187bb1e into main Sep 10, 2026
53 of 69 checks passed
@edersonbrilhante
edersonbrilhante deleted the feat-scale-set-example branch September 10, 2026 18:19
edersonbrilhante added a commit that referenced this pull request Sep 17, 2026
## Description

Restore the multi-runner scale-set orchestration example removed by
revert PR #5403, replacing merged PR #5378.

The example provides the Terraform configuration, provider locks,
outputs, and documentation needed to deploy an ECS scale-set controller
with the EC2 runner compute provider. It is intentionally limited to the
example and its generated/provider metadata; the reusable MiniStack
fixture support and ECS/MockServer lifecycle smoke test are provided by
the follow-up PRs.

## Test Plan

- Terraform formatting passed through the repository hooks.
- Merge-conflict checks passed.
- Parent-branch Terraform checks passed after the idle-configuration
correction.
- No live AWS deployment was performed for this example-only PR; CI
validation remains the authoritative deployment check.

## Related Issues

Depends on #5350. Replaces #5378.

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
edersonbrilhante added a commit that referenced this pull request Sep 25, 2026
## Description

Consolidates the complete experimental GitHub Actions runner scale-set
stack into one PR. It provides the Terraform orchestration, the ECS
controller that consumes it, the EC2 compute-provider implementation,
the example deployment, and the validation and delivery workflows needed
to operate the stack.

### Status and implementation basis

- This stack is experimental and its interfaces and behavior may evolve
as the scale-set integration matures.
- The scale-set service was written based on reverse-engineering the
behavior and protocol implemented by the Go code in
[`actions/scaleset`](https://github.com/actions/scaleset), which
provides the GitHub Actions Runner Scale Set API client and
message-session primitives.
- Additional user-facing and operational documentation can be added in a
follow-up PR. This PR therefore focuses on the implementation,
integration coverage, and delivery plumbing; documentation-only jobs are
not required to gate this PR.

### Terraform and AWS orchestration

- Adds the standalone `modules/orchestration-providers/scale-set`
module, which deploys one hardened ECS Fargate controller service per
resolved controller group, with private networking, security groups,
CloudWatch logging, health checks, deployment rollback, and
task-definition safeguards.
- Routes scale-set lanes through the provider-aware multi-runner and
runner-config composition, with plan-known grouping by compute provider,
runner configuration, or explicit membership.
- Delivers versioned non-secret reconciler configuration through SSM
Parameter Store while keeping GitHub App credentials as SSM references
and restricting task- and compute-role permissions to the configured
resources.
- Adds validation for GitHub scope and scale-set ownership, grouping
coverage, plan-time inputs, provider contracts, configuration and
task-definition limits, reserved environment variables, wildcard IAM
actions, and AWS inline-policy quotas.
- Defines the compute-provider capability boundary and implements the
EC2 adapter for scale-up, tagging, termination, JIT configuration
storage, AMI access, owned-runner discovery, and scale-down
reconciliation.

### Scale-set controller and runtime

- Adds the reusable GitHub Actions scale-set client for GitHub.com,
GHES, and data-residency endpoints, including GitHub App authentication,
runner-group and scale-set discovery, JIT configuration, runner removal,
and message-session handling.
- Adds the long-running ECS controller service with SSM-backed
configuration loading, independent reconcilers, liveness/readiness
endpoints, bounded shutdown, and session recovery.
- Reconciles EC2 capacity from assigned jobs, preserves busy or unknown
runners during scale-down, tracks provider-owned instances with tags,
and supports task-role or assumed-role credentials.
- Keeps sensitive tokens, message bodies, and JIT configurations out of
manifests and logs; TLS verification changes are scoped to the relevant
client.

### Example, CI, and integration coverage

- Adds the `examples/multi-runner-scale-set` deployment, provider locks,
outputs, documentation, and the required multi-runner wiring.
- Adds Dependabot and CI coverage for formatting, linting,
Terraform/OpenTofu tests, TypeScript tests and builds,
multi-architecture container builds, and release publication with SBOM,
provenance, and registry attestations.
- Adds a hardened scale-set container smoke test using a read-only
filesystem, dropped capabilities, `no-new-privileges`, and no network
access.
- Adds MiniStack ECS/MockServer lifecycle coverage for image build and
push, controller startup, GitHub App and scale-set protocol requests,
runner registration, scale-up, scale-down, EC2 termination, and cleanup.
- The Terraform module adopts scale sets that already exist in GitHub by
name; it does not create or delete GitHub scale-set resources.

### Merged stack contributions

This PR now contains the following merged scale-set PRs:

-
[#5350](#5350)
— wire scale-set orchestration through the provider-aware runner
configuration.
-
[#5405](#5405)
— restore the multi-runner scale-set example and its generated/provider
metadata. This replaces the earlier
[#5378](#5378)
example PR.
-
[#5300](#5300)
— add the ECS scale-set controller, client, and EC2 provider runtime.
-
[#5347](#5347)
— add documentation, CI, release, and MiniStack integration support.
-
[#5375](#5375)
— add the scale-set service-container and ECS/MockServer lifecycle smoke
coverage, included through #5347.

## Test Plan

- Added and updated focused Terraform/OpenTofu tests for the scale-set
module, computed inputs, grouping, ownership validation, configuration
delivery, IAM policy construction, quota checks, and configuration
resolution.
- Added TypeScript unit tests covering the scale-set client, HTTP and
message-session behavior, service configuration and credentials,
controller lifecycle and health, and EC2 provider inventory and
reconciliation.
- Terraform/OpenTofu formatting, validation, current-interface
documentation generation, `tofu test`, TypeScript
type-check/build/format/lint/test targets, container smoke tests, and
MiniStack lifecycle workflows cover the affected paths.
- Broader user-facing and operational documentation is intentionally
deferred to a separate PR, so documentation-only jobs do not need to be
required for this PR.
- `git diff --check` and the repository CI workflows were run for the
combined stack.

## Related Issues

- Builds on the multi-runner v2 interface from
[#5367](#5367).
- The scale-set service implementation is informed by
[`actions/scaleset`](https://github.com/actions/scaleset).
- This PR is the Terraform and deployment stack consumed by the
scale-set controller and service changes listed above.

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Guilherme Caulada <guilherme.caulada@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant