GitHub Actions — Level by Level›Level 2 · Cheat sheet & self-check

Level 2 — Secure and scale · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

05 · Actions Runner Controller

Install (Helm, OCI charts)

helm install arc -n arc-systems --create-namespace oci://ghcr.io/actions/actions-runner-controller-charts/gha-runner-scale-set-controllerThe controller
helm install arc-runner-set -n arc-runners --create-namespace -f values.yaml oci://ghcr.io/actions/actions-runner-controller-charts/gha-runner-scale-setA runner scale set
runs-on: arc-runner-setWorkflows target the scale set by its installation name

Inspect

kubectl get pods -n arc-systemsController and listener pods
kubectl get pods -n arc-runners -wRunner pods appearing per job
kubectl get autoscalingrunnersets,ephemeralrunners -AARC's custom resources

06 · OIDC federation & secret hygiene

OIDC in a workflow

permissions: { id-token: write, contents: read }Allow the job to request an OIDC token
aws-actions/configure-aws-credentials (role-to-assume)AWS: assume an IAM role
google-github-actions/auth (workload_identity_provider)GCP: Workload Identity Federation
azure/login (client-id, tenant-id, subscription-id)Azure: federated credential
hashicorp/vault-action (method: jwt)Vault: JWT auth role

Subject claims to trust

repo:acme/infra:ref:refs/heads/mainMain branch of one repo
repo:acme/infra:environment:prodJobs using the prod environment
repo:acme/infra:pull_requestPull request runs (read-only roles only)

07 · Supply chain: sign, attest, scan, verify

In the pipeline

syft ghcr.io/acme/api@$DIGEST -o spdx-json > sbom.jsonGenerate an SBOM
trivy image --exit-code 1 --severity CRITICAL ghcr.io/acme/api@$DIGESTFail on critical vulnerabilities
cosign sign --yes ghcr.io/acme/api@$DIGESTKeyless signing (OIDC identity of the workflow)
cosign attest --yes --type spdxjson --predicate sbom.json ghcr.io/acme/api@$DIGESTAttach the SBOM as a signed attestation
actions/attest-build-provenance (subject-name, subject-digest, push-to-registry)GitHub artifact attestation (SLSA provenance)

Verifying

cosign verify --certificate-identity-regexp '^https://github.com/acme/' --certificate-oidc-issuer https://token.actions.githubusercontent.com IMAGE@DIGESTVerify a keyless signature
gh attestation verify oci://ghcr.io/acme/api@$DIGEST --owner acmeVerify a GitHub attestation

08 · Hardening the runner

Isolation

Ephemeral runners (one job per runner)No state or malware survives between jobs
Separate runner pools/scale sets per trust levelUntrusted PRs never share runners with deploy jobs
Runner groups → selected repositoriesLimit which repos can use which runners
Dedicated, tainted nodes for runnersKeep CI pods away from production workloads

Workflow hygiene

uses: owner/action@<full commit SHA>Pin third-party actions
permissions: {} at top, grant per jobLeast-privilege GITHUB_TOKEN
Avoid pull_request_target + checkout of PR codeClassic secret-exfiltration path
NetworkPolicy egress allow-list for runner podsLimit where a compromised job can send data