Bare metal runners

Heavy CI, priced like the machine.

Connect a GitHub organization. Forge opens an isolated namespace and registers a runner scale set that wakes for jobs and scales to zero when the queue is empty.

Workflow

jobs:
  build:
    runs-on: forge-acme
    steps:
      - uses: actions/checkout@v4
      - run: make test
1. Connect

An owner installs the Forge GitHub App on the organization. Forge never asks for a password or a personal access token.

2. Isolate

Each customer gets a namespace. Kyverno applies a network policy, a resource quota, and baseline pod security before any runner starts.

3. Run

Jobs ask for the customer label. The scale set listener starts runners only while work is waiting.

Why teams move the heavy jobs

GitHub-hostedForge
Large jobsBilled per minute at the size you select.Runs on the metal already in the cluster. Idle runners scale to zero.
NeighborsShared GitHub infrastructure.One namespace per customer. No path to the cluster API or to another customer.
SetupPick a runner size in the workflow.Install the app, then change runs-on.