landing-zone-github-runners
Type: regulative
Decision
Every landing zone must have its own private GitHub runners provisioned inside its VNet.
Why
Public runners have no network path to the PaaS data plane once public access is denied.
Violations
- Application team using a separate VNet for runner integration.
- Runner label implying capability differences instead of network accessibility.
Anchor
no-platform-ops
Implements
Files
- landing-zones/bicep/modules/base/virtualNetwork.bicep
- .github/utils/create-landingzone-gh-runners.ps1
- .github/workflows/template-landing-zones.yml
Links
- platform-identity-github (depends-on) — Runner registration needs the GitHub App, as no other identity can register runners to a repo.
← Back to knowledge graph