Skip to content

Choose a tag to compare

@c4po c4po released this 19 Mar 02:53
· 1 commit to main since this release
516322d

Purpose

This action helps organizations enforce that GitHub workflows only run on approved self-hosted runners, rather than GitHub-hosted runners. Since GitHub Enterprise Cloud doesn't provide a direct option to disallow GitHub-hosted runners, this action serves as a workaround:

  1. Set up this action as a required workflow for all repositories in your GitHub organization
  2. The action analyzes workflow files to ensure all runners are in an allowed list
  3. Workflows using unapproved runners will fail, allowing you to enforce your organization's runner policy

Usage

Add this action as a required workflow in your GitHub organization:

name: Validate Workflow Runners

on:
  workflow_dispatch:
  pull_request:
    paths:
      - '.github/workflows/**'
  push:
    paths:
      - '.github/workflows/**'

jobs:
  validate-runners:
    name: Validate Workflow Runners
    runs-on: ubuntu-latest
    steps:
      - name: Checkout repository
        uses: actions/checkout@v3
        
      - name: Validate runners
        uses: c4po/workflow-runner-analyzer@v1
        with:
          allowed-runners: 'self-hosted my-org-runner-1 my-org-runner-2'

Inputs

Input Description Required Default
allowed-runners Space-separated list of allowed runner names Yes None