forgejo/tests/integration/fixtures/TestAPIUserActionsRunnerOperations/action_runner.yml
Manuel Ganter 5b6bbabd74 feat: implement ephemeral runners (#9962)
As described in [this comment](https://gitea.com/gitea/act_runner/issues/19#issuecomment-739221) one-job runners are not secure when running in host mode. We implemented a routine preventing runner tokens from receiving a second job in order to render a potentially compromised token useless. Also we implemented a routine that removes finished runners as soon as possible.

Big thanks to [ChristopherHX](https://github.com/ChristopherHX) who did all the work for gitea!

Rel: #9407

## Checklist

The [contributor guide](https://forgejo.org/docs/next/contributor/) contains information that will be helpful to first time contributors. There also are a few [conditions for merging Pull Requests in Forgejo repositories](https://codeberg.org/forgejo/governance/src/branch/main/PullRequestsAgreement.md). You are also welcome to join the [Forgejo development chatroom](https://matrix.to/#/#forgejo-development:matrix.org).

### Tests

- I added test coverage for Go changes...
  - [ ] in their respective `*_test.go` for unit tests.
  - [x] in the `tests/integration` directory if it involves interactions with a live Forgejo server.
- I added test coverage for JavaScript changes...
  - [ ] in `web_src/js/*.test.js` if it can be unit tested.
  - [ ] in `tests/e2e/*.test.e2e.js` if it requires interactions with a live Forgejo server (see also the [developer guide for JavaScript testing](https://codeberg.org/forgejo/forgejo/src/branch/forgejo/tests/e2e/README.md#end-to-end-tests)).

### Documentation

- [ ] I created a pull request [to the documentation](https://codeberg.org/forgejo/docs) to explain to Forgejo users how to use this change.
- [ ] I did not document these changes and I do not expect someone else to do it.

### Release notes

- [ ] I do not want this change to show in the release notes.
- [ ] I want the title to show in the release notes with a link to this pull request.
- [ ] I want the content of the `release-notes/<pull request number>.md` to be be used for the release notes instead of the title.

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/9962
Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org>
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
Co-authored-by: Manuel Ganter <manuel.ganter@think-ahead.tech>
Co-committed-by: Manuel Ganter <manuel.ganter@think-ahead.tech>
2026-02-16 18:56:56 +01:00

46 lines
1 KiB
YAML

- id: 71301
uuid: "99fc4a58-a25e-4dbe-b6ea-3d55dddcd216"
name: "runner-1-user"
version: "dev"
owner_id: 2
repo_id: 0
description: "A superb runner"
agent_labels: ["debian", "gpu"]
deleted: 0
- id: 71302
uuid: "9d32fe29-be59-4cd6-a97b-b6abb6937d47"
name: "runner-2-user"
version: "11.3.1"
owner_id: 1
repo_id: 0
description: "A splendid runner"
agent_labels: ["docker"]
deleted: 0
- id: 71303
uuid: "70bc0da3-35b2-4129-bbc9-4679dfdda4d0"
name: "runner-3-user"
version: "11.3.1"
owner_id: 2
repo_id: 0
description: "Another fine runner"
agent_labels: ["fedora"]
deleted: 0
- id: 71304
uuid: "3873c473-47b8-4559-9fa5-843277419780"
name: "runner-4-global"
version: "11.3.1"
owner_id: 0
repo_id: 0
description: ""
agent_labels: []
deleted: 0
- id: 71305
uuid: "3ca04a95-3e75-4e48-8b7a-63427ebcf3b8"
name: "runner-5-user-ephemeral"
version: "1.0.0"
owner_id: 2
repo_id: 0
description: "An ephemeral runner"
agent_labels: ["ephemeral-label"]
ephemeral: true
deleted: 0