Bake images and smoke PRs in your own KILN🔥
kiln v0.2.5: self-hosted GitHub Actions on hardware you already own, with one fresh rootless QEMU/KVM VM per job. Why build this Two of our repositories ran their PR smoke gates on Google Cloud Build. Over a 27-day window that came to 396 builds and 2,192 build-minutes: about 81 minutes a day, or roughly $39 a month on E2_HIGHCPU_8 . That is not a big number. But a box with an i9-14900KF (32…
A self-hosted GitHub Actions solution is presented in the form of kiln v0.2.5, which uses hardware already owned by the user. The system operates a fresh rootless QEMU/KVM VM for each job, providing a clean environment without the need for root access, tap devices or bridges. The kiln serve binary with an embedded dashboard polls GitHub for queued jobs, creates a throwaway Ubuntu 24.04 VM for each, assigns a single-use runner, and deletes the VM afterward. The system uses a Rust binary, a Docker Hub mirror, and a systemd user service.
The kiln bake process builds images based on the Ubuntu 24.04 cloud image and a cloud-init recipe, installing packages, the actions/runner release, and requested Node versions. The kernel is extracted to base.vmlinuz, and a disk.qcow2 is created, backed by the frozen base. QEMU boots the kernel directly, with no initrd or bootloader, and virtio and ext4 are built into the Ubuntu kernel.
Each job runs on a fresh VM with its own disk, cache, and overlays, ensuring isolation and clean environments. The system uses count-based scheduling for job assignment, taking into consideration the number of queued jobs, booting time, and idle jobs. A reaper removes surplus idle VMs, and deregistration handles the race to ensure the VM is deleted if GitHub refuses due to a newly picked-up job.
The kiln system also includes a prejob hook that runs before the first step of each job, checking for fork pull requests or workflows triggered by other repositories. If such events are detected, the hook fails the job, and the VM is deleted. However, this blind spot can be exploited by running fork code in workflows triggered by issue_comment events, so those workflows are recommended to be run on GitHub-hosted runners on public repositories.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.