Documentation

Configuration, environments, and secrets

Keep GitHub Actions workflow configuration in GitHub and make the smallest runner-label change first.

Workflow configuration

Runzivo does not replace the GitHub Actions workflow format. Keep triggers, permissions, actions, environment settings, and steps in your repository workflow file. Start by changing only runs-on.

Use the same workflow review process you use for any CI change. The V1 design lets GitHub assign a job to an eligible repository-scoped runner.

workflow.yml
jobs:
  test:
    runs-on: rzv-ubuntu-24.04-x64-2vcpu-8gb
    environment: stg
    steps:
      - uses: actions/checkout@v7
      - run: ./ci/test.sh

Secrets and variables

Manage repository and environment secrets in GitHub. A workflow step can read any secret GitHub makes available to that job, so use least privilege and do not print secrets in logs.

The V1 design does not add repository secrets to runner configuration. It keeps platform credentials and control-plane secrets out of customer workers.

Network-dependent jobs

The V1 security baseline uses isolated workers with host-enforced network controls. If a job cannot reach a required internal service or external endpoint, contact support with the endpoint and job details before moving a production workflow.