[workshop-sync] side-quest-24-01-runner-infrastructure.md: ephemeral/JIT runner and proxy-env-var guidance unsupported by self-hosted-runners re
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- javascript
- Domain
- documentation
Research direction
Start with workshop/side-quest-24-01-runner-infrastructure.md and compare its runner and network guidance with the linked self-hosted-runners reference. Update the ephemeral/JIT and proxy sections to match the documented runner configuration and network isolation, and align the MCP server explanation with network.allowed. Done when the inaccurate claims are corrected and the issue’s listed accurate examples remain intact.
Written by the indexing model from the issue text.
Description
Workshop file reviewed
workshop/side-quest-24-01-runner-infrastructure.md
Problem
- The "Ephemeral and JIT runners" section states:
Ephemeral runners are destroyed after a single job ... Register one using the ephemeral flag ... Just-in-time (JIT) runners are provisioned on demand and deregistered immediately after use. They require a registration token scoped to your organisation or repository and are typically managed by a runner controller such as actions-runner-controller.
This section links to https://github.github.com/gh-aw/reference/self-hosted-runners/, but that page contains no mention of ephemeral runners, JIT runners, registration tokens, or actions-runner-controller registration flags.
- The "Proxy and network requirements" section instructs learners to set host-level proxy environment variables:
HTTPS_PROXY=(proxy.example.com/redacted) HTTP_PROXY=(proxy.example.com/redacted) NO_PROXY=localhost,127.0.0.1,github.example.com
This is not documented anywhere in the gh-aw reference docs as the mechanism for self-hosted runner network configuration.
- The "Network isolation" section frames "MCP tool servers" as independently-reachable endpoints, separate from
network.allowed.
Current correct behaviour
The actual reference/self-hosted-runners/ page documents:
- The
runs-onfrontmatter field (string/array/object forms) to target self-hosted runners. require_self_hosted_runnersin.github/workflows/aw.json(or--require-self-hosted-runnersCLI flag) to enforce self-hosted runners on all generated jobs.- ARC Docker-in-Docker topology via
runner.topology: arc-dind, includingGH_AW_DOCKER_SOCK_PATH/GH_AW_DOCKER_SOCK_GIDenv var overrides for split-daemon setups. - Network isolation is enforced via AWF's own internal Docker network topology (an internal
awf-netbridge with no internet route) and a dual-homed Squid proxy inside the Docker daemon's domain — not via host-levelHTTPS_PROXY/HTTP_PROXY/NO_PROXYenv vars on the runner machine. - Documented outbound network requirements:
api.githubcopilot.com(or enterprise Copilot endpoint),github.com(or GHES instance),ghcr.io(to pull the MCP gateway image), and any domains innetwork.allowed.
Suggested fix
- Remove or rewrite the "Ephemeral and JIT runners" section to cover gh-aw-documented self-hosted runner configuration instead:
runs-on,require_self_hosted_runners, andrunner.topology: arc-dindfor ARC DinD setups. - Replace the HTTPS_PROXY/HTTP_PROXY/NO_PROXY guidance with an explanation of AWF's internal Squid-proxy network isolation and the documented outbound endpoint list (Copilot/model endpoint, GitHub/GHES, ghcr.io, plus
network.alloweddomains). - Reframe "MCP tool servers" access as governed by the
network.allowedfrontmatter field rather than a separately reachable endpoint category. - The
network.allowedexample andfirewall.mdartifact mention in this file are accurate and do not need changes.
Reference: https://github.github.com/gh-aw/reference/self-hosted-runners/ (confirmed reachable, HTTP 200; verified no "ephemeral"/"JIT"/proxy-env-var content present)
Generated by 🔍 Workshop Sync Check · copilot · auto · 239.5 AIC · ⌖ 8.28 AIC · ⊞ 9.2K · ◷
- expires on Oct 12, 2026, 5:49 AM UTC
- Dominant language
- JavaScript
- Stars
- 52
- Forks
- 26
- Avg merge
- 12h 58m
- Merged PRs (30d)
- 15
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from githubnext/gh-aw-workshop
-
documentation
Difficulty 1/5 Under an hour Newbie friendliness 91/100
githubnext/gh-aw-workshop#4458 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
githubnext/gh-aw-workshop#4456 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 73/100
githubnext/gh-aw-workshop#4455 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
githubnext/gh-aw-workshop#4454 ·
Maintainers usually reply within 1 day
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
githubnext/gh-aw-workshop#4451 ·
Maintainers usually reply within 1 day
All issues in githubnext/gh-aw-workshop
Similar issues
-
enhancement good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
anoopcodehack/DevBoard#609 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
openai/codex-plugin-cc#813 ·
-
area: ops type: test
Difficulty 2/5 1-3 hours Newbie friendliness 79/100
accensa/x402-facilitator-stellar#559 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
bilawalsidhu/gods-eye-view#1060 ·
Maintainers usually reply within 1 day
-
Progress difficulty filter lists Hard before MediumPossibly taken @Pandamachi claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
sysprog21/codetrial#281 · 1 comment ·
Maintainers usually reply within 1 day