mirror of
https://github.com/actions-runner-controller/actions-runner-controller.git
synced 2026-09-30 01:31:27 +02:00
523 lines
18 KiB
YAML
523 lines
18 KiB
YAML
## By default .Release.namespace is used
|
|
namespaceOverride: ""
|
|
|
|
scaleset:
|
|
# Name of the scaleset
|
|
name: ""
|
|
runnerGroup: "default"
|
|
# Labels are optional list of strings that will be applied to the scaleset
|
|
# allowing scaleset to be selected by the listener based on the labels specified in the workflow.
|
|
# https://docs.github.com/en/actions/how-tos/manage-runners/self-hosted-runners/apply-labels
|
|
labels: []
|
|
## minRunners is the min number of idle runners. The target number of runners created will be
|
|
## calculated as a sum of minRunners and the number of jobs assigned to the scale set.
|
|
# minRunners: 0
|
|
## maxRunners is the max number of runners the autoscaling runner set will scale up to.
|
|
# maxRunners: 5
|
|
|
|
# Auth object provides authorization parameters.
|
|
# You should apply either:
|
|
# 1) secretName referencing the secret containing authorization parameters in the same namespace where the scale set is being installed in
|
|
# 2) app object parameters
|
|
# 3) github_tokne
|
|
#
|
|
# If multiple of them are set, only single one will be applied based on the above mentioned order.
|
|
auth:
|
|
url: "" # Required
|
|
githubToken: ""
|
|
secretName: ""
|
|
app:
|
|
clientId: ""
|
|
installationId: ""
|
|
privateKey: ""
|
|
|
|
# secretResolution configures how secrets are resolved for this scale set.
|
|
# By default, secrets are resolved using Kubernetes secrets. When Kubernetes
|
|
# secrets are used, no proxy config will be applied.
|
|
#
|
|
# If you decide to use secret integrations with vaults, you can configure
|
|
# proxy settings for the vault communication here.
|
|
secretResolution:
|
|
# Name of the secret resolver to use.
|
|
# Available values:
|
|
# - "kubernetes" - use Kubernetes secrets
|
|
# - "azureKeyVault" - use Azure Key Vault (rendered as the API type "azure_key_vault")
|
|
type: "kubernetes"
|
|
## Proxy settings when type is NOT "kubernetes"
|
|
# proxy:
|
|
# http:
|
|
# url: http://proxy.com:1234
|
|
# credentialSecretRef: proxy-auth # a secret with `username` and `password` keys
|
|
# https:
|
|
# url: http://proxy.com:1234
|
|
# credentialSecretRef: proxy-auth # a secret with `username` and `password` keys
|
|
# noProxy:
|
|
# - example.com
|
|
# - example.org
|
|
|
|
## Configuration for Azure Key Vault integration.
|
|
## auth.secretName selects the Azure secret containing the GitHub app/token configuration.
|
|
## azureKeyVault.secretKey is not supported; it was never used by the API/resolver
|
|
## and is now rejected rather than silently ignored. Set auth.secretName explicitly.
|
|
# azureKeyVault:
|
|
# url: ""
|
|
# clientId: ""
|
|
# tenantId: ""
|
|
# certificatePath: ""
|
|
|
|
## Proxy can be used to define proxy settings that will be used by the
|
|
## controller, the listener and the runner of this scale set.
|
|
# proxy:
|
|
# http:
|
|
# url: http://proxy.com:1234
|
|
# credentialSecretRef: proxy-auth # a secret with `username` and `password` keys
|
|
# https:
|
|
# url: http://proxy.com:1234
|
|
# credentialSecretRef: proxy-auth # a secret with `username` and `password` keys
|
|
# noProxy:
|
|
# - example.com
|
|
# - example.org
|
|
|
|
## A self-signed CA certificate for communication with the GitHub server can be
|
|
## provided using a config map key selector. If `runnerMountPath` is set, for
|
|
## each runner pod ARC will:
|
|
## - create a `github-server-tls-cert` volume containing the certificate
|
|
## specified in `certificateFrom`
|
|
## - mount that volume on path `runnerMountPath`/{certificate name}
|
|
## - set NODE_EXTRA_CA_CERTS environment variable to that same path
|
|
## - set RUNNER_UPDATE_CA_CERTS environment variable to "1" (as of version
|
|
## 2.303.0 this will instruct the runner to reload certificates on the host)
|
|
##
|
|
## If any of the above had already been set by the user in the runner pod
|
|
## template, ARC will observe those and not overwrite them.
|
|
## Example configuration:
|
|
#
|
|
# githubServerTLS:
|
|
# certificateFrom:
|
|
# configMapKeyRef:
|
|
# name: config-map-name
|
|
# key: ca.crt
|
|
# runnerMountPath: /usr/local/share/ca-certificates/
|
|
|
|
## Resource object allows modifying resources created by the chart itself
|
|
## Labels and annotations are independently optional for each resource.
|
|
resource:
|
|
# Specifies metadata that will be applied to all resources managed by ARC
|
|
all:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the AutoscalingRunnerSet resource
|
|
autoscalingRunnerSet:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the AutoscalingListener resource
|
|
# created by the AutoscalingRunnerSet controller.
|
|
autoscalingListener:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the listener ServiceAccount.
|
|
listenerServiceAccount:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the listener Role.
|
|
listenerRole:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the listener RoleBinding.
|
|
listenerRoleBinding:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the listener config Secret.
|
|
listenerConfigSecret:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the EphemeralRunnerSet resource.
|
|
ephemeralRunnerSet:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the EphemeralRunner resource.
|
|
ephemeralRunner:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the EphemeralRunner config Secret.
|
|
ephemeralRunnerConfigSecret:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the manager Role resource
|
|
managerRole:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
extraRules: []
|
|
|
|
# Specifies metadata that will be applied to the manager RoleBinding resource
|
|
managerRoleBinding:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the no-permission ServiceAccount
|
|
# (created for non-kubernetes runner modes).
|
|
noPermissionServiceAccount:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the kubernetes-mode RoleBinding
|
|
# (created when runner.mode is "kubernetes" and a ServiceAccountName is not provided).
|
|
kubernetesModeRoleBinding:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
|
|
# Specifies metadata that will be applied to the kubernetes-mode Role.
|
|
kubernetesModeRole:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
extraRules: []
|
|
|
|
# Specifies metadata that will be applied to the kubernetes-mode ServiceAccount.
|
|
kubernetesModeServiceAccount:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
# TODO: Add more resource customizations when needed
|
|
|
|
# Template applied for the runner container
|
|
runner:
|
|
# Mode can be used to automatically add configuration for the selected mode
|
|
# The available modes are:
|
|
# - "" (default) - no additional configuration is applied
|
|
# - "kubernetes" - configuration for running jobs in Kubernetes mode is applied
|
|
# - "dind" - configuration for running jobs in Docker-in-Docker mode is
|
|
#
|
|
# For each mode, we provide configuration out of the box that works for most use
|
|
# cases. You can customize our configuration by modifying the fields below,
|
|
# or you can leave mode empty and provide your own complete configuration.
|
|
mode: ""
|
|
|
|
pod:
|
|
metadata:
|
|
labels: {}
|
|
annotations: {}
|
|
# Runner pod template customization.
|
|
#
|
|
# All fields under runner.pod.spec (except those listed below) are applied directly to
|
|
# spec.template.spec of the generated runner pod.
|
|
#
|
|
# Special handling:
|
|
# - spec.containers: appended after the generated "runner" container (name "runner" is reserved)
|
|
# - spec.initContainers: appended after any generated initContainers (e.g. dind mode)
|
|
# - spec.volumes: appended after generated volumes
|
|
# In empty mode, only user-supplied volumes and the optional GitHub server TLS
|
|
# volume are included.
|
|
# - spec.restartPolicy: defaults to Never; an explicit Kubernetes restart policy is preserved
|
|
#
|
|
# Note: serviceAccountName is managed by the chart and cannot be overridden via runner.pod.spec.
|
|
spec:
|
|
# The name "runner" is reserved and must not be used here.
|
|
containers: []
|
|
initContainers: []
|
|
volumes: []
|
|
|
|
# Applied to the container named "runner" in every mode; its name cannot be overridden.
|
|
# image and command use the defaults below when omitted. Other container fields
|
|
# (e.g. resources, securityContext, args) are passed through, including false/zero values.
|
|
# env entries replace mode defaults by name; volumeMounts replace them by mountPath.
|
|
# Replacements are whole entries, not merged maps. Unspecified mode defaults remain.
|
|
# TLS defaults also respect an existing mount named github-server-tls-cert.
|
|
# Duplicate env names or mountPaths within a list are rejected.
|
|
# Overrides of Docker/hook env or mounts must remain compatible with the selected mode.
|
|
# In dind/kubernetes mode, the older runner.env is still read, but container.env takes precedence.
|
|
container:
|
|
image: "ghcr.io/actions/actions-runner:latest"
|
|
command: ["/home/runner/run.sh"]
|
|
|
|
dind:
|
|
# If official runner image is used, or the dind image doesn't contain
|
|
# assets from the /home/runner/externals directory, copy externals
|
|
# starts the init container whose purpose is to prepare the environment
|
|
# for the dind container.
|
|
copyRunnerExternals: true
|
|
dockerGroupId: "123"
|
|
dockerSock: "unix:///var/run/docker.sock"
|
|
waitForDockerInSeconds: 120
|
|
container:
|
|
image: "docker:dind"
|
|
# Additional container fields are passed through as-is (e.g. resources, imagePullPolicy, ports, etc.)
|
|
# env: []
|
|
# volumeMounts: []
|
|
# args: [] # overrides the chart-generated dockerd args
|
|
# startupProbe: {} # overrides the chart-generated startupProbe
|
|
|
|
kubernetesMode:
|
|
serviceAccountName: ""
|
|
hookPath: "/home/runner/k8s/index.js"
|
|
requireJobContainer: true
|
|
# workVolumeClaim configures the *ephemeral* PVC used for the runner work directory
|
|
# (mounted at /home/runner/_work).
|
|
#
|
|
# This maps directly to `spec.template.spec.volumes[].ephemeral.volumeClaimTemplate.spec`.
|
|
# Any fields you set here are merged onto the chart defaults.
|
|
#
|
|
# Defaults:
|
|
# - accessModes: ["ReadWriteOnce"]
|
|
# - storageClassName: "local-path"
|
|
# - resources.requests.storage: "1Gi"
|
|
workVolumeClaim: {}
|
|
# workVolumeClaim:
|
|
# accessModes: ["ReadWriteOnce"]
|
|
# storageClassName: "fast-ssd"
|
|
# resources:
|
|
# requests:
|
|
# storage: 10Gi
|
|
# extensionRef: ""
|
|
# extension:
|
|
## metadata adds metadata to the config map configured for the hook extension
|
|
## NOTE: namespace field is ignored.
|
|
# metadata:
|
|
# labels: ""
|
|
# namespace: ""
|
|
# yaml:
|
|
# metadata:
|
|
# annotations:
|
|
# spec:
|
|
# containers: []
|
|
|
|
## controllerServiceAccount is the service account of the controller
|
|
controllerServiceAccount:
|
|
namespace: ""
|
|
name: ""
|
|
|
|
# listener specific configuration. This configuration is applied to the listener component of the chart.
|
|
listener:
|
|
# scaler is config applied to the kubernetes client component of the listener.
|
|
# Both values must be integers greater than 0.
|
|
scaler:
|
|
# qps is the sustained rate of requests the listener may issue to the Kubernetes API server.
|
|
qps: 50
|
|
# burst is the number of requests the listener may issue to the Kubernetes API server in a burst.
|
|
burst: 100
|
|
## podTemplate is the PodSpec for each listener Pod
|
|
## For reference: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#PodSpec
|
|
# podTemplate:
|
|
# spec:
|
|
# containers:
|
|
# # Use this section to append additional configuration to the listener container.
|
|
# # If you change the name of the container, the configuration will not be applied to the listener,
|
|
# # and it will be treated as a side-car container.
|
|
# - name: listener
|
|
# securityContext:
|
|
# runAsUser: 1000
|
|
# # Use this section to add the configuration of a side-car container.
|
|
# # Comment it out or remove it if you don't need it.
|
|
# # Spec for this container will be applied as is without any modifications.
|
|
# - name: side-car
|
|
# image: example-sidecar
|
|
## metrics configuration for the listener.
|
|
## In order to avoid helm merging these fields, we left the metrics commented out.
|
|
## When configuring metrics, please uncomment the metrics object below.
|
|
## You can modify the configuration to add or remove labels or specify custom buckets for histograms.
|
|
##
|
|
## The example below lists every metric and every label the listener can export, together with the
|
|
## default buckets. It is not identical to the built-in defaults used when listener.metrics is not set: the
|
|
## labels marked "not exposed by default" ("job_workflow_ref", "job_workflow_name" and
|
|
## "job_workflow_target") are opt-in, so remove them to keep the default label set. If the buckets
|
|
## field is not specified, the default buckets will be applied.
|
|
##
|
|
## "job_workflow_ref" and "job_workflow_target" contain the git ref the workflow ran from (for example
|
|
## refs/heads/<branch> or refs/pull/<number>/merge), so every branch and pull request creates a new
|
|
## time series per job. On histograms this is multiplied by the number of buckets. Only keep these
|
|
## labels when your metrics backend can handle the resulting cardinality.
|
|
# metrics:
|
|
# counters:
|
|
# gha_started_jobs_total:
|
|
# labels:
|
|
# [
|
|
# "repository",
|
|
# "organization",
|
|
# "enterprise",
|
|
# "job_name",
|
|
# "event_name",
|
|
# # not exposed by default:
|
|
# "job_workflow_ref",
|
|
# "job_workflow_name",
|
|
# "job_workflow_target",
|
|
# ]
|
|
# gha_completed_jobs_total:
|
|
# labels:
|
|
# [
|
|
# "repository",
|
|
# "organization",
|
|
# "enterprise",
|
|
# "job_name",
|
|
# "event_name",
|
|
# "job_result",
|
|
# # not exposed by default:
|
|
# "job_workflow_ref",
|
|
# "job_workflow_name",
|
|
# "job_workflow_target",
|
|
# ]
|
|
# gauges:
|
|
# gha_assigned_jobs:
|
|
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
# gha_running_jobs:
|
|
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
# gha_registered_runners:
|
|
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
# gha_busy_runners:
|
|
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
# gha_min_runners:
|
|
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
# gha_max_runners:
|
|
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
# gha_desired_runners:
|
|
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
# gha_idle_runners:
|
|
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
# histograms:
|
|
# gha_job_startup_duration_seconds:
|
|
# labels:
|
|
# [
|
|
# "repository",
|
|
# "organization",
|
|
# "enterprise",
|
|
# "job_name",
|
|
# "event_name",
|
|
# # not exposed by default:
|
|
# "job_workflow_ref",
|
|
# "job_workflow_name",
|
|
# "job_workflow_target",
|
|
# ]
|
|
# buckets:
|
|
# [
|
|
# 0.01,
|
|
# 0.05,
|
|
# 0.1,
|
|
# 0.5,
|
|
# 1.0,
|
|
# 2.0,
|
|
# 3.0,
|
|
# 4.0,
|
|
# 5.0,
|
|
# 6.0,
|
|
# 7.0,
|
|
# 8.0,
|
|
# 9.0,
|
|
# 10.0,
|
|
# 12.0,
|
|
# 15.0,
|
|
# 18.0,
|
|
# 20.0,
|
|
# 25.0,
|
|
# 30.0,
|
|
# 40.0,
|
|
# 50.0,
|
|
# 60.0,
|
|
# 70.0,
|
|
# 80.0,
|
|
# 90.0,
|
|
# 100.0,
|
|
# 110.0,
|
|
# 120.0,
|
|
# 150.0,
|
|
# 180.0,
|
|
# 210.0,
|
|
# 240.0,
|
|
# 300.0,
|
|
# 360.0,
|
|
# 420.0,
|
|
# 480.0,
|
|
# 540.0,
|
|
# 600.0,
|
|
# 900.0,
|
|
# 1200.0,
|
|
# 1800.0,
|
|
# 2400.0,
|
|
# 3000.0,
|
|
# 3600.0,
|
|
# ]
|
|
# gha_job_execution_duration_seconds:
|
|
# labels:
|
|
# [
|
|
# "repository",
|
|
# "organization",
|
|
# "enterprise",
|
|
# "job_name",
|
|
# "event_name",
|
|
# "job_result",
|
|
# # not exposed by default:
|
|
# "job_workflow_ref",
|
|
# "job_workflow_name",
|
|
# "job_workflow_target",
|
|
# ]
|
|
# buckets:
|
|
# [
|
|
# 0.01,
|
|
# 0.05,
|
|
# 0.1,
|
|
# 0.5,
|
|
# 1.0,
|
|
# 2.0,
|
|
# 3.0,
|
|
# 4.0,
|
|
# 5.0,
|
|
# 6.0,
|
|
# 7.0,
|
|
# 8.0,
|
|
# 9.0,
|
|
# 10.0,
|
|
# 12.0,
|
|
# 15.0,
|
|
# 18.0,
|
|
# 20.0,
|
|
# 25.0,
|
|
# 30.0,
|
|
# 40.0,
|
|
# 50.0,
|
|
# 60.0,
|
|
# 70.0,
|
|
# 80.0,
|
|
# 90.0,
|
|
# 100.0,
|
|
# 110.0,
|
|
# 120.0,
|
|
# 150.0,
|
|
# 180.0,
|
|
# 210.0,
|
|
# 240.0,
|
|
# 300.0,
|
|
# 360.0,
|
|
# 420.0,
|
|
# 480.0,
|
|
# 540.0,
|
|
# 600.0,
|
|
# 900.0,
|
|
# 1200.0,
|
|
# 1800.0,
|
|
# 2400.0,
|
|
# 3000.0,
|
|
# 3600.0,
|
|
# ]
|