Skip to content

FireRunner

Run every GitLab CI job in its own Firecracker microVM, on your own hardware.

FireRunner is a GitLab Runner custom executor. gitlab-runner picks up jobs as usual. For each job FireRunner hands out a new microVM, runs every stage in it and deletes it when the job ends.

Shell executor Docker executor FireRunner
Isolation none containers, shared kernel own VM and kernel per job
Leftovers from earlier jobs files, processes, images images, volumes none
docker build host Docker privileged DinD or socket Docker in the VM, not privileged
Other projects' files and images readable readable with the host socket or privileged DinD out of reach

Isolation has a cost: jobs take longer than on a shell executor, whose host keeps every project's images and layers at hand.

Quick start

  1. On a Linux host with /dev/kvm and a blank disk:

    curl -sfL https://raw.githubusercontent.com/ismoilovdevml/firerunner/main/install.sh | sudo bash
    
  2. In GitLab, create a runner with the tag firecracker and copy its glrt- token.

  3. Register it and check the host:

    sudo firerunner runner register --url https://gitlab.example.com --token -   # paste the glrt-... token
    sudo firerunner doctor
    
  4. Send a job to it:

    test:
      tags: [firecracker]
      script:
        - echo "running in $(hostname)"
    

Where next