Your own network on AWS

Start AWS machines in your own subnets and security groups, so jobs reach what that network reaches.

By default, AWS machines start in a network SuperCI makes for jobs in each region, with no way in: nothing can reach a job’s machine, and jobs cannot reach your other machines’ private addresses.

Sometimes a job needs to reach something private: a database, an internal registry, a GitHub Enterprise server. Then give a region a network of your own.

Set it

Runners → AWS → Your own network. One line for each region:

us-east-1 subnet-0abc… subnet-0def… sg-0123…

Name the subnets machines may start in and the security groups they get. Machines in that region then start there, and reach whatever that network reaches. What a job may reach is yours to set, in those security groups.

Subnets without public addresses

Add the word private for subnets with no public addresses:

us-east-1 subnet-0abc… sg-0123… private

Machines there get no public address. They still have to reach GitHub (or GitLab) and AWS, so the subnets need a NAT gateway or the equivalent.

What to know

  • A network that cannot be found stops jobs in that region. They do not fall back to another network.
  • Regions you do not list keep using the network SuperCI made.
  • A job that moves to another provider (see Order and limits) does not reach this network from there. Name AWS in the label (superci-aws) for jobs that depend on it.