3 ms·
This is pretty cool and one of the few things I couldn't find a viable alternative to in-house hosting so far. The only thing your "GitLab Runners as a Service"
by lclc 2mo ago
This is pretty cool and one of the few things I couldn't find a viable alternative to in-house hosting so far. The only thing your "GitLab Runners as a Service" is missing is ISO 27001 (and optionally SOC 2) certification. That makes it again easier for your customer to get / maintain their ISO 27001.
(So far I used this cloud.init script to spin up and upgrade GitLab-Runner instants: https://gitlab.com/21analytics/gitlab-runner-cloud-init/-/blob/master/gitlab-runner.init?ref_type=heads https://gitlab.com/21analytics/gitlab-runner-cloud-init/-/bl...)
- inanothertime 2mo agoHa, let us look into ISO 27001 certification and see what it takes to obtain it (and SOC 2). Thank you for this valuable pointer! If you could just sign in (accounts are free and you can even try us out for the first 48h and not be charged), then we could message you to your email address once we have an update here.
- senorrib 2mo agoYou’re on for a ride. Set at least 50k on the side for that.
- lclc 2mo agoI clicked 'Get started -> Login with GitLab.com' but for my tastes it wants way too much access just to add a runner: > Grants complete read/write access to the API, including all groups and projects, the container registry, the dependency proxy, and the package registry. Even more so just to stay informed about updates.
- inanothertime 2mo ago> it wants way too much access just to add a runner We wanted to make the onboarding as simple as possible so that we can: 0. Log you in through your existing GitLab.com or GitLab self-hosted account 1. List all your groups and projects to decide where to install the runner 2. Disable GitLab.com's own instance runners (otherwise our Runners are not picked up) 3. Install the Runner 4. Optionally: When installing an agent runner, we are able to reply to read and reply to all your issues where you tag us via `@Rocket` -- this runs completely on your machine that we host for you! It doesn't run on our infrastructure and we only access your runner machine for auto-cleaning its caches. That's really all the RocketRunner does with you granting us permissions when logging in. We are looking into ways how to possible scope access better! Thanks for your feedback!