diff --git a/.github/workflows/runner-full-stack-e2e.yml b/.github/workflows/runner-full-stack-e2e.yml index 5c144c5339..632f5c2a74 100644 --- a/.github/workflows/runner-full-stack-e2e.yml +++ b/.github/workflows/runner-full-stack-e2e.yml @@ -95,7 +95,7 @@ jobs: AWS_PAID_RUNNER_ENABLED: ${{ vars.RUNNER_E2E_AWS_ENABLED }} run: | set -euo pipefail - github_runner='ubuntu-latest-m' + github_runner='ubuntu-latest' aws_runner='runs-on/fleet=paperclip-public-pr-x64/env=public-ci' if [ "$AWS_PAID_RUNNER_ENABLED" = true ]; then @@ -111,7 +111,7 @@ jobs: echo "max_parallel_default=32" echo "max_parallel_limit=57" } >> "$GITHUB_OUTPUT" - echo '::notice title=Paid runner routing::RUNNER_E2E_AWS_ENABLED is not true; using the existing paid runner' + echo '::notice title=Paid runner routing::RUNNER_E2E_AWS_ENABLED is not true; using the proven GitHub-hosted runner' fi catalog: diff --git a/tests/runner-e2e/README.md b/tests/runner-e2e/README.md index c7d9cb1320..b66c7da8fe 100644 --- a/tests/runner-e2e/README.md +++ b/tests/runner-e2e/README.md @@ -288,8 +288,8 @@ by the repository variable `RUNNER_FULL_STACK_E2E_NIGHTLY_ENABLED=true`. Set it only after the live acceptance ladder in the architecture plan is green. Set `RUNNER_E2E_AWS_ENABLED=true` to route paid cells to the repository-scoped ephemeral AWS RunsOn fleet selected by -`runs-on/fleet=paperclip-public-pr-x64/env=public-ci`. Any other value retains -the existing `ubuntu-latest-m` target. Set `RUNNER_E2E_MAX_PARALLEL` to an +`runs-on/fleet=paperclip-public-pr-x64/env=public-ci`. Any other value uses the +proven GitHub-hosted `ubuntu-latest` target. Set `RUNNER_E2E_MAX_PARALLEL` to an integer from 1–100 on AWS (default 100); use at least 71 to run the current complete catalog in one wave. The fallback runner retains its 1–57 limit and default of 32. Multi-turn steps are sequential inside their cell while diff --git a/tests/runner-e2e/SECURITY.md b/tests/runner-e2e/SECURITY.md index 19f407bb76..d23deff204 100644 --- a/tests/runner-e2e/SECURITY.md +++ b/tests/runner-e2e/SECURITY.md @@ -67,9 +67,10 @@ the actor gate, environment branch restriction, and protected default branch. When `RUNNER_E2E_AWS_ENABLED=true`, paid matrix cells use the exact RunsOn fleet selector `runs-on/fleet=paperclip-public-pr-x64/env=public-ci`, matching the AWS fleet selected by `pr-trusted.yml` only after its stable numeric-ID trust gate. -Any other or missing toggle value falls back to the existing `ubuntu-latest-m` -paid runner and its lower concurrency ceiling. The workflow chooses between -those two reviewed literal labels; it never evaluates a configured runner label. +Any other or missing toggle value falls back to the GitHub-hosted +`ubuntu-latest` runner and its lower concurrency ceiling. The workflow chooses +between those two reviewed literal labels; it never evaluates a configured +runner label. Keep both runner targets restricted to `paperclipai/paperclip` and workflows that independently authorize trusted source revisions. Never let a fork or diff --git a/tests/runner-e2e/workflow-security.test.ts b/tests/runner-e2e/workflow-security.test.ts index 8359b70448..fd685b597a 100644 --- a/tests/runner-e2e/workflow-security.test.ts +++ b/tests/runner-e2e/workflow-security.test.ts @@ -71,7 +71,7 @@ describe("public repository paid workflow security", () => { expect(authorizeJob).toContain( "aws_runner='runs-on/fleet=paperclip-public-pr-x64/env=public-ci'", ); - expect(authorizeJob).toContain("github_runner='ubuntu-latest-m'"); + expect(authorizeJob).toContain("github_runner='ubuntu-latest'"); expect(authorizeJob).toContain( "AWS_PAID_RUNNER_ENABLED: ${{ vars.RUNNER_E2E_AWS_ENABLED }}", );