APURV
  • Home
  • Journey
  • Projects
  • Blogs
  • Interview
  • Exams
Resume
APURV

Building scalable, secure, and production-ready cloud infrastructure. Automation first.

NAVIGATION

HomeExperienceProjectsCertificationsSkills

TECH STACK

AWSGCPK8sCI/CDLinuxDocker

CONNECT

LinkedInGitHubEmailResume

© 2026 Apurv Gujjar. All rights reserved.
Apurv Gujjar
Apurv GujjarDevOps & Cloud Engineer
|Interview Documentation
Portfolio
Handbooks
🎯Linux🐙Git & GitHub🤖GitHub Actions🌐Networking☁AWS🛠Terraform🐳Docker☸Kubernetes📊Monitoring🛡DevSecOps💰Cost Optimization🚨Incident Scenarios👤HR & Behavioral☁GCP🐍Python
Interview DocumentationGitHub ActionsWhat security measures must be put in place when operating self-hosted runners?
Back to all GitHub Actions questions
Q17

What security measures must be put in place when operating self-hosted runners?

💬Answer
  • Never use self-hosted runners for public repositories: Fork pull requests can run arbitrary code on your private servers (remote code execution).
  • Use Ephemeral Runners: Configure runners to register, execute exactly one job, and automatically deregister and self-destruct (using transient containers or auto-scaling groups).
  • Network Isolation: Place runners in private subnets with no public inbound rules; allow outbound HTTPS connections to GitHub endpoints only.
  • Non-Root Execution: Run the runner agent process using a non-privileged system user (USER runner).

Related GitHub Actions Questions

View All GitHub ActionsQuestions →
Q1

What is GitHub Actions, and how does it process workflows under the hood?

Q2

Can you list and explain the key architectural components of GitHub Actions?

Q3

How do you configure workflow triggers, and what is the syntax for defining manual execution parameters?

Q4

What is a matrix strategy in GitHub Actions, and in what scenarios would you use it?

Apurv Gujjar - DevOps & Cloud Engineer
Created by

Apurv Gujjar

DevOps & Cloud Engineer

Specialized in:DevOpsAWSGCPKubernetesTerraformDocker
View Portfolio