Skip to content

Zero-infra hosted-runner lane + TCG fallback; lead README with Falco proof - #1

Merged
ErenAri merged 4 commits into
mainfrom
hosted-runner-onramp
Jun 14, 2026
Merged

ErenAri merged 4 commits into
mainfrom
hosted-runner-onramp

Conversation

@ErenAri

@ErenAri ErenAri commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Why

GitHub-hosted ubuntu-latest runners now expose /dev/kvm (proven by the Falco modern_bpf PoC run), so the full QEMU VM compatibility gate no longer needs a self-hosted runner. The repo previously told users the opposite. This makes the zero-infra path the headline and hardens it.

What

  • New .github/workflows/bpfcompat-example-hosted.yml — runs the VM gate on stock ubuntu-latest, installs its own deps, reports KVM status as a notice/warning.
  • internal/vm/qemu.go — falls back to TCG software emulation (-accel tcg -cpu max) when /dev/kvm is absent instead of failing the launch. Split into pure machineArgsFor(arch, kvm) + kvmAvailable(), covered by TestMachineArgsForAccelFallback.
  • README — new top sections: CO-RE/BTFHub wedge, "Try it in CI — no self-hosted runner", and the Falco modern_bpf 5-kernel proof table (red ubuntu-20.04-5.4 UNSUPPORTED_MAP_TYPE).
  • Fixed stale "self-hosted required / hosted has no KVM" claims in README + firecracker-preflight.yml; recorded the lane in docs/falco-parity.md + CHANGELOG.

Verification

go build ./..., go vet, gofmt, and go test ./internal/vm/ all pass. New workflow YAML validates. Worth dispatching bpfcompat-example-hosted.yml once on this PR to confirm hosted KVM end-to-end before relying on it publicly — the TCG fallback means a KVM-less runner degrades to slow, not broken.

🤖 Generated with Claude Code

ErenAri and others added 2 commits June 14, 2026 15:38
…lco proof

GitHub-hosted ubuntu-latest runners now expose /dev/kvm (proven by the Falco
modern_bpf PoC run), so the full QEMU VM compatibility gate no longer needs a
self-hosted runner. Make that the headline on-ramp and harden it:

- New .github/workflows/bpfcompat-example-hosted.yml runs the VM gate on stock
  ubuntu-latest; reports KVM status, installs its own deps.
- QEMU executor falls back to TCG software emulation (-accel tcg -cpu max) when
  /dev/kvm is absent instead of failing the launch. Split into a pure
  machineArgsFor(arch, kvm) with TestMachineArgsForAccelFallback.
- README leads with the CO-RE/BTFHub wedge, the no-self-hosted-runner path, and
  the Falco modern_bpf 5-kernel proof (red ubuntu-20.04-5.4 UNSUPPORTED_MAP_TYPE).
- Fix stale "self-hosted/GitHub-hosted has no KVM" claims in README and
  firecracker-preflight.yml; record the lane in docs/falco-parity.md + CHANGELOG.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Adds the trust signals that were missing (SBOM + cosign signing already
shipped in release-artifacts.yml):

- .github/workflows/codeql.yml: CodeQL Go analysis (build-mode none, so no
  C/libbpf toolchain needed), security-and-quality queries, on push/PR/weekly.
- .github/workflows/scorecard.yml: OpenSSF Scorecard, publishes to the public
  Scorecard API and uploads SARIF to code scanning.
- .github/dependabot.yml: weekly grouped updates for Go modules and the pinned
  GitHub Actions.
- README: CI / CodeQL / Scorecard / license badges + a Supply-chain posture
  section with a cosign verify-blob example.
- docs/supply-chain.md: in-repo controls table plus a checklist of
  maintainer-side repo settings that can't be set from files (branch
  protection, secret-scanning push protection, OpenSSF Best Practices badge
  registration).

No untrusted github.event.* input is interpolated into any run: step in the
new workflows.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
ErenAri and others added 2 commits June 14, 2026 15:47
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Layer 4 supply-chain trust signals: CodeQL, Scorecard, Dependabot
@ErenAri
ErenAri merged commit 5afc59c into main Jun 14, 2026
5 of 8 checks passed
@ErenAri
ErenAri deleted the hosted-runner-onramp branch June 14, 2026 12:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant