Run scans and policy evaluations on customer-managed runners
By default, Discovery scans and policy evaluations run on Pulumi-managed runners. With customer-managed runners, they run on runners you host in your own infrastructure instead, using the same runner pools that can also run Pulumi Deployments.
Benefits
Running scans and policy evaluations on customer-managed runners provides several advantages:
- Data residency: Keep scan data and policy evaluations within your private network.
- Private infrastructure access: Scan resources in fully private VPCs and environments that aren’t accessible from the public internet.
- Compliance: Meet regulatory requirements by ensuring cloud provider credentials never leave your network.
- Flexible hosting: Host runners on any hardware and environment that meets your needs, including Linux and macOS.
How it works
Runners poll Pulumi Cloud for pending work and execute it in your environment. A single runner can handle deployments, Discovery scans, and policy evaluations. For the execution model, the full list of what runs on customer-managed runners, and the configuration reference, see Customer-managed runners.
Each kind of work picks a pool in this order:
- Discovery scans: the cloud account’s pool, then the organization default pool, then the Pulumi hosted pool. A scan started through the REST API can name a different pool for that one scan.
- Policy evaluations: the audit policy group’s pool, then the organization default pool, then the Pulumi hosted pool. Only audit policy groups use a runner pool. Preventative policy groups run inside
pulumi upandpulumi previewwherever the CLI runs.
Set up
Set up Discovery scans
- Set up a customer-managed runner pool.
- Navigate to Resources > Discovery in Pulumi Cloud.
- Select the runner pool for the account you want to scan.
- Trigger a scan and confirm it completes successfully.
Set up policy evaluations
- Set up a customer-managed runner pool.
- Navigate to Governance > Policy configuration in Pulumi Cloud and select the Policy Groups tab.
- Select the runner pool for an audit policy group.
- Run a policy evaluation against a stack and confirm the results appear as expected.
Use an organization default pool
If you want every account scan and policy evaluation to use a customer-managed pool by default, set an organization default runner pool. When set, scans and audit policy groups without an explicit pool use the organization default instead of the Pulumi hosted pool.
Restrict workflow types
By default, runners handle all workflow types (deployments, Discovery scans, and policy evaluations). You can restrict which workflow types a runner handles using the enabled_workflow_types configuration option in pulumi-workflow-agent.yaml:
enabled_workflow_types:
- insights_scan
- policy_evaluation
For the full list of configuration options, see the configuration reference.