landing-zone-github-runners
Type: decision
Decision
Every landing zone has its own private GitHub runners provisioned inside the landing zone VNet.
Why
Public runners have no network path to PaaS data plane once public access is denied.
Violations
- Application team using a separate VNet for runner integration.
- Runner label that implies capability differences instead of network accessibility.
Links
- platform-identity-github — Runner registration requires the GitHub App — no other identity has the permissions to register runners to a repo.
← Back to knowledge graph