FireRunner¶
Run every GitLab CI job in its own Firecracker microVM, on your own hardware.
FireRunner is a GitLab Runner custom executor. gitlab-runner picks up jobs as usual. For each job FireRunner hands out a new microVM, runs every stage in it and deletes it when the job ends.
| Shell executor | Docker executor | FireRunner | |
|---|---|---|---|
| Isolation | none | containers, shared kernel | own VM and kernel per job |
| Leftovers from earlier jobs | files, processes, images | images, volumes | none |
docker build |
host Docker | privileged DinD or socket | Docker in the VM, not privileged |
| Other projects' files and images | readable | readable with the host socket or privileged DinD | out of reach |
Isolation has a cost: jobs take longer than on a shell executor, whose host keeps every project's images and layers at hand.
Quick start¶
-
On a Linux host with
/dev/kvmand a blank disk:curl -sfL https://raw.githubusercontent.com/ismoilovdevml/firerunner/main/install.sh | sudo bash -
In GitLab, create a runner with the tag
firecrackerand copy itsglrt-token. -
Register it and check the host:
sudo firerunner runner register --url https://gitlab.example.com --token - # paste the glrt-... token sudo firerunner doctor -
Send a job to it:
test: tags: [firecracker] script: - echo "running in $(hostname)"
Where next¶
- Writing
.gitlab-ci.yml: Writing jobs - Running the hosts: Install, Configuration, Operations
- Behind a proxy or with internal registries: Corporate networks
- How it works and what it protects: How it works
- Commands, metrics and limits: Reference