What to verify before you go organisation-wide
BYOC security checklist
A short checklist covering isolation, credentials, networking and audit for a BYOC deployment review.
Short enough that people finish it. Each item maps to a page with the detail.
- Runners are in private subnets with no public IP
- IMDSv2 is enforced and the metadata hop limit is 1
- The instance profile is scoped to the cache bucket and nothing else
- Deployment credentials use OIDC, not stored keys
- Egress policy runs in enforce mode with a reviewed allowlist
- Runner groups restrict which repositories can schedule work
- GITHUB_TOKEN defaults to read-only, elevated per job
- Third-party actions are pinned to commit SHAs
- Audit log export to your SIEM is configured
- max_capacity is set as a budget guardrail
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.