Skip to content

Customer-operated Actions capacity

GitHub sends demand. Gondola dispatches your AWS fleet.

A small, highly available supervisor for policy-defined, one-job EC2 runners. It installs in your existing VPC and keeps your code, credentials, and execution path in your account.

Dispatch manifestAWS / 01
Source
GitHub scale-set demand
Control
2 × Fargate tasks
Fence
Lease + deployment generation
Compute
Ephemeral EC2
Network
Existing customer VPC
Storage
Coordination metadata only
Job path remains in your account

Controller

Active / passive

Coordination

Short-lived lease

Capacity

x64 + ARM64

Runner

One job / hard expiry

Operating sequence

A supervisor, not someone else’s runtime.

Gondola turns assigned GitHub demand into customer-approved AWS capacity, then makes sure that capacity is retired. The policy stays declarative; the execution stays yours.

One job per runner · hard lifetime limit
01
Demand

Observe assigned work

The active controller long-polls GitHub for jobs assigned to a declared fleet. There is no public webhook endpoint to operate.

02
Policy

Resolve an approved fleet

Repository code selects a stable label. Terraform—not the workflow—owns the image, network, IAM role, architecture, and capacity policy behind it.

03
Capacity

Start a one-job runner

Gondola requests an EC2 instance in your VPC, supplies a short-lived just-in-time configuration, and tracks the lifecycle through termination.

04
Recovery

Fail over without split-brain

Two controller tasks share a generation-fenced lease. A standby takes over only after the active generation expires, and runners retain an independent lifetime limit.

Trust boundary / 04 controls

The control plane is part of your infrastructure.

The system is designed so a vendor service is not required to receive job payloads, proxy source, hold workload credentials, or keep an active build alive.

Inspect the security model

No inbound product endpoint

Controllers and runners initiate outbound HTTPS. Security groups do not need a public listener for Gondola.

Secrets stay in your account

The GitHub App key remains in Secrets Manager and workload permissions remain on customer IAM roles.

Coordination, not job storage

DynamoDB carries a short lease, deployment generation, and readiness state—not source, logs, workflow payloads, or usage billing.

Releases can be verified

The delivery contract includes digest-pinned images, signed checksums, provenance, SBOMs, and narrow Terraform-managed permissions.

IMDSv2 requiredEncrypted EBSRootless controllerRead-only filesystemSigned artifacts

Simple subscriptions / USD

Price the organization, not the workload.

The subscription is tied to covered GitHub organizations. It does not vary with repositories, job count, runtime, runner count, AWS accounts, or regions. Infrastructure remains on your AWS bill.

Hobby

$0for personal work

For personal projects you own and maintain yourself.

  • One GitHub user or personal organization
  • Public or private repositories
  • AWS usage billed directly to you
Start free

Stripe Checkout · $0 · no card

Most common

Business

$99monthly · $990 yearly

For one private GitHub organization.

  • Unlimited covered repositories and jobs
  • Any supported AWS accounts or regions
  • Email support
Choose Business

Stripe Checkout · 30-day trial

Enterprise

$599monthly · $5,990 yearly

For up to 10 organizations, including private repositories.

  • Everything in Business
  • One fixed ten-organization bundle
  • Additional ten-organization blocks
Choose Enterprise

30-day trial · Stripe Checkout

AWS infrastructure, taxes, and separately agreed services are not included.

Operator notes

A few good questions before deployment.

01Where does a workflow execute?+

On an ephemeral EC2 instance in an AWS account you control. You provide the VPC, subnets, security groups, instance profiles, and supported instance types.

02What is hosted by Gondola?+

Nothing in the job path. The controller is hosted on ECS Fargate in the customer account and communicates directly with GitHub and AWS.

03Why are there two controllers?+

They provide active/passive availability across Availability Zones. A conditional DynamoDB lease and deployment generation ensure that only one task publishes capacity at a time.

04What does the subscription cover?+

The maintained controller, Terraform installer, signed releases, upgrade material, and support. AWS bills the infrastructure directly to you.

05Which platforms are supported?+

The current release targets GitHub.com and Linux EC2 fleets on x64 or ARM64. Windows, macOS, GitHub Enterprise Server, Azure, and Google Cloud are not currently supported.

Pick the right operating scope

Choose a plan. Install in AWS. Keep the job path yours.

Compare plans