A job runs in a throwaway VM on a Mac that belongs to someone in your organization, and talks to GitHub directly. HiveWorker decides which machine takes the job. It does not handle the job's code, logs or secrets.
A developer's Mac
Throwaway Linux VM
GitHub's runner, one job, then destroyed
HiveWorker daemon
Runs as your user, not root. No inbound ports.
The Mac's files and keychain stay outside the VM.
GitHub
The job, its logs and its artifacts
HiveWorker coordinator
Presence and job assignment. No job data
The App has no permission for code, repository contents or secrets. It asks for these five permissions and no others.
| Permission | Access | What it is for |
|---|---|---|
| Self-hosted runnersOrganization | Read and write | Create the hive runner scale sets and register a one-time runner for each job. |
| MembersOrganization | Read | Check that a person adding a machine belongs to your organization, and to the teams you allow. |
| ActionsRepository | Read | Receive workflow job events, so a queued job can be matched to a free machine. |
| MetadataRepository | Read | Required by GitHub for every App. |
| Email addressesAccount | Read | Sign in with GitHub. |
It subscribes to these events: workflow_job, organization, membership, team, installation_repositories. Because the App cannot read contents, a job's checkout happens inside the VM with the token GitHub gives that job.
The coordinator is the HiveWorker service that matches queued jobs to free machines. It is not in a job's data path. The runner inside the VM talks to GitHub directly for the job, its logs and its artifacts.
HiveWorker is in early access and has not had an external security audit. To report a problem, write to auth@thecomputerplumbers.com.