A Kubernetes operator maintained by GitHub and deployed with Helm. It manages and automatically scales self-hosted GitHub Actions runners inside your own clusters.
Also called ARC.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Actions Runner Controller in context, with comparison tables and the common traps.
Terms in this definition
- GitHub Actions
Event-driven workflow automation in GitHub, started by things like a push or pull request. Typical uses include deploying Bicep or CLI templates and launching Azure Machine Learning jobs with no manual step.
Related terms
- Azure Arc Setup
Connecting a server to Arc becomes a guided job: this optional component sets up the agent for connected machines through a wizard, then leaves an icon in the notification area. Shipped with Windows Server 2025 as a Feature on Demand.
- Azure Policy for Kubernetes
Admission control for Kubernetes based on Gatekeeper v3, installed as an AKS add-on or, on other clusters, an Arc extension. It acts as a webhook so that non-compliant pods are rejected by Azure Policy definitions set to Deny.
- Defender sensor
DaemonSet from Defender for Containers that runs on each node and gathers runtime telemetry with eBPF for threat detection. AKS gets it as a security profile; EKS and GKE get it as an Arc extension.
- Gauge
Shows progress on one number towards its target as a circular arc in a Power BI report.
- HIMDS
Part of the Azure Connected Machine agent; on a server connected through Arc, it offers instance metadata and tokens for the managed identity through a local endpoint.
- Hybrid agent extension applications
Only accounts in this local group, on a server connected through Arc, are allowed to ask HIMDS for tokens issued to the machine's managed identity.
- Integrated vulnerability assessment
A Qualys-powered extension for Defender for Servers, now retired and replaced by Defender Vulnerability Management. It scanned Arc machines and Windows and Linux Azure VMs, though not scale set instances.