Bare metal runners
Connect a GitHub organization. Forge opens an isolated namespace and registers a runner scale set that wakes for jobs and scales to zero when the queue is empty.
Workflow
jobs:
build:
runs-on: forge-acme
steps:
- uses: actions/checkout@v4
- run: make test
An owner installs the Forge GitHub App on the organization. Forge never asks for a password or a personal access token.
Each customer gets a namespace. Kyverno applies a network policy, a resource quota, and baseline pod security before any runner starts.
Jobs ask for the customer label. The scale set listener starts runners only while work is waiting.
| GitHub-hosted | Forge | |
|---|---|---|
| Large jobs | Billed per minute at the size you select. | Runs on the metal already in the cluster. Idle runners scale to zero. |
| Neighbors | Shared GitHub infrastructure. | One namespace per customer. No path to the cluster API or to another customer. |
| Setup | Pick a runner size in the workflow. | Install the app, then change runs-on. |