finds.dev← search

// the find

cattle-ops/terraform-aws-gitlab-runner

★ 628 · HCL · MIT · updated Oct 2026

Terraform module for AWS GitLab runners on ec2 (spot) instances

A Terraform module that stands up autoscaling GitLab CI runners on AWS EC2, using spot instances to cut compute costs. It's for teams self-hosting GitLab runners on AWS who want IaC-managed autoscaling instead of hand-rolled EC2/ASG setups, and it supports three topologies: single docker-machine agent, multiple agents with shared S3 cache, or plain docker (no autoscaling).

The input surface is genuinely well-documented — every object() variable (runner_instance, runner_gitlab, runner_manager, etc.) has inline descriptions baked into the schema and rendered via terraform-docs, not a separate doc that drifts from the code. It ships a dedicated terminate-agent-hook Lambda that hooks into the ASG lifecycle to drain jobs before termination, which is the part people usually get wrong by hand. Security defaults are sane out of the box: IMDSv2 required, SSM access instead of open SSH, optional KMS-managed key for CloudWatch/logs. CI is substantial — checkov, trivy, gitleaks, tflint, and megalinter all run on every PR, plus renovate for dependency bumps.

The core runner-worker model (docker+machine, see docker_machine_fleet.tf) depends on docker-machine, which Docker archived years ago — the module works around this with a community-maintained CKI fork, but you're building production infra on a dead upstream tool unless you opt into docker-autoscaler instead. The variable surface is cluttered with deprecated inputs still wired into main.tf (registration_token, access_token_secure_parameter_store_name, runner_gitlab_registration_config) that are kept for back-compat but add real cognitive overhead when reading the docs for the first time. The two linked migration guides for v7 and v8 in the README signal this module has a history of breaking config.toml/variable shape across majors, so pin your version and budget time to read the migration script before upgrading. There's no visible terratest or plan/apply integration suite — correctness relies on linters plus manual review, not automated apply-time verification against real AWS state.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →