A B C D E F G H I J K L M N O P Q R S T U V W Z
Sa Sc Se Sf Sh Si Sm Sn So Sp Sq St Su Sy
Sea Sec Sel Sen Sep Ser Ses

Self-Hosted Runner Security

Self-hosted runner security is the protection of CI/CD execution workers that the organization runs in its own infrastructure rather than using fully managed vendor-hosted runners. It matters because self-hosted runners often have more network reach and persistence than managed ephemeral workers.

What is Self-Hosted Runner Security?

These runners can be powerful but risky because they may retain state between jobs, access internal systems, or run untrusted code from pull requests or partner integrations. Hardening focuses on isolation, trust boundaries, cleanup, and permission scope.

What Self-Hosted Runner Security Commonly Supports

Common uses include CI/CD hardening, internal build isolation, secure deployment automation, and runner governance.

Self-Hosted Runner Security vs. Managed Ephemeral Runner Model

Self-hosted runners give more control but often more risk if not isolated carefully. Managed ephemeral runners usually reduce some persistence and infrastructure burden.

Frequently Asked Questions

Why are self-hosted runners risky?

Because they may bridge untrusted code execution with sensitive internal access or long-lived machine state.

Should teams avoid self-hosted runners entirely?

Not necessarily. They can be necessary, but they should be treated as sensitive infrastructure.

Related Cybersecurity Terms

George Mutune

I am a cyber security professional with a passion for delivering proactive strategies for day to day operational challenges. I am excited to be working with leading cyber security teams and professionals on projects that involve machine learning & AI solutions to solve the cyberspace menace and cut through inefficiency that plague today's business environments.