Skip to content

What to verify before you go organisation-wide

BYOC security checklist

A short checklist covering isolation, credentials, networking and audit for a BYOC deployment review.

Short enough that people finish it. Each item maps to a page with the detail.

  1. Runners are in private subnets with no public IP
  2. IMDSv2 is enforced and the metadata hop limit is 1
  3. The instance profile is scoped to the cache bucket and nothing else
  4. Deployment credentials use OIDC, not stored keys
  5. Egress policy runs in enforce mode with a reviewed allowlist
  6. Runner groups restrict which repositories can schedule work
  7. GITHUB_TOKEN defaults to read-only, elevated per job
  8. Third-party actions are pinned to commit SHAs
  9. Audit log export to your SIEM is configured
  10. max_capacity is set as a budget guardrail

Your next build could be twice as fast, at half the price

Start free. Migrating away is the same one line, and we publish that diff too.