Sign inSign up

prismsoft/arc-automation

By prismsoft

•Updated 8 months ago

Image
0

437

prismsoft/arc-automation repository overview

⁠ARC Automation Service

GitHub Actions Runner Controller (ARC) automation service that automatically deploys repository-specific runners when a GitHub App is installed.

⁠Features

  • GitHub App Authentication: Works with Repository Admin permissions only (no Organization access required)
  • Automatic Runner Deployment: Creates RunnerDeployment automatically on GitHub App installation
  • Auto-scaling: Dynamic runner management via HorizontalRunnerAutoscaler
  • Webhook-driven: Real-time event processing
  • Kubernetes-native: Integrates seamlessly with K8s cluster

⁠Quick Start

⁠Prerequisites
  • Kubernetes cluster (v1.24+)
  • ARC Controller installed in cluster
  • GitHub App with required permissions
⁠Run with Docker
docker run -d \
  -p 8080:8080 \
  -e GITHUB_APP_ID=<your-app-id> \
  -e GITHUB_WEBHOOK_SECRET=<your-webhook-secret> \
  -v /path/to/private-key.pem:/etc/github/private-key.pem:ro \
  prismsoft/arc-automation:latest

Deploy to Kubernetes

# Create secrets
kubectl create secret generic arc-automation-secret \
  --from-literal=GITHUB_APP_ID=<your-app-id> \
  --from-literal=GITHUB_WEBHOOK_SECRET=<your-webhook-secret> \
  -n arc-automation

kubectl create secret generic github-app-private-key \
  --from-file=private-key.pem=<path-to-private-key> \
  -n arc-automation

# Deploy
kubectl apply -k https://github.com/your-org/arc-automation/k8s

Image Tags
┌─────────────┬───────────────────────┐
│     Tag     │      Description      │
├─────────────┼───────────────────────┤
│ latest      │ Latest stable release │
├─────────────┼───────────────────────┤
│ 0.1.0       │ Specific version      │
├─────────────┼───────────────────────┤
│ 0.1.0-amd64 │ AMD64 architecture    │
├─────────────┼───────────────────────┤
│ 0.1.0-arm64 │ ARM64 architecture    │
└─────────────┴───────────────────────┘
Environment Variables
┌─────────────────────────────┬─────────────────────────────────┬──────────┬─────────────────────────────┐
│          Variable           │           Description           │ Required │           Default           │
├─────────────────────────────┼─────────────────────────────────┼──────────┼─────────────────────────────┤
│ GITHUB_APP_ID               │ GitHub App ID                   │ Yes      │ -                           │
├─────────────────────────────┼─────────────────────────────────┼──────────┼─────────────────────────────┤
│ GITHUB_APP_PRIVATE_KEY_PATH │ Private key file path           │ No       │ /etc/github/private-key.pem │
├─────────────────────────────┼─────────────────────────────────┼──────────┼─────────────────────────────┤
│ GITHUB_WEBHOOK_SECRET       │ Webhook secret for verification │ Yes      │ -                           │
└─────────────────────────────┴─────────────────────────────────┴──────────┴─────────────────────────────┘
Architecture

GitHub App Installation
        ↓ (webhook)
┌───────────────────────┐
│   ARC Automation      │
│   (Spring Boot)       │
└───────────────────────┘
        ↓
┌───────────────────────┐
│   Kubernetes          │
│  - RunnerDeployment   │
│  - Autoscaler         │
└───────────────────────┘
        ↓
┌───────────────────────┐
│   ARC Controller      │
│  - Manage Runner Pods │
└───────────────────────┘

Workflow

1. Repository admin installs GitHub App
2. GitHub sends webhook (installation.created)
3. Service generates Installation Token
4. Creates K8s Secret with token
5. Deploys RunnerDeployment and HorizontalRunnerAutoscaler
6. ARC Controller registers runners
7. PR creation triggers workflow → Runner Pod auto-created

Endpoints
┌──────────────────┬────────┬─────────────────────────────┐
│     Endpoint     │ Method │         Description         │
├──────────────────┼────────┼─────────────────────────────┤
│ /webhook/github  │ POST   │ GitHub webhook receiver     │
├──────────────────┼────────┼─────────────────────────────┤
│ /webhook/health  │ GET    │ Health check                │
├──────────────────┼────────┼─────────────────────────────┤
│ /actuator/health │ GET    │ Spring Boot actuator health │
└──────────────────┴────────┴─────────────────────────────┘
Health Check

Built-in health check runs every 30 seconds:
HEALTHCHECK --interval=30s --timeout=3s --start-period=10s --retries=3 \
    CMD wget --no-verbose --tries=1 --spider http://localhost:8080/actuator/health || exit 1

Technical Stack

- Runtime: Java 21 (Eclipse Temurin JRE)
- Framework: Spring Boot 3.2.2
- Kubernetes: Fabric8 Kubernetes Client 6.10.0
- Authentication: JWT with BouncyCastle for GitHub App
- Base Image: Alpine Linux (minimal footprint)

Security

- Runs as non-root user (UID 1000)
- Minimal Alpine-based image
- Private key mounted as read-only volume
- Webhook signature verification

Repository & Documentation

- GitHub: https://github.com/your-org/arc-automation
- Issues: https://github.com/your-org/arc-automation/issues
- Documentation: https://github.com/your-org/arc-automation/blob/main/README.md

License

MIT License

Support

For questions and support, please open an issue on GitHub.

Tag summary

Content type

Image

Digest

sha256:6fef1b549…

Size

121.2 MB

Last updated

8 months ago

docker pull prismsoft/arc-automation