Official agent skill

Depot GitHub Runners

by PostHog in PostHog/posthog-foss

Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners.

OfficialMITAuto-check passedDevOps & Cloud

Install Depot GitHub Runners

skills CLI
$ npx skills add PostHog/posthog-foss --skill depot-github-runners -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PostHog/posthog-foss depot-github-runners --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/depot-github-runners .claude/skills/depot-github-runners && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
depot-github-runners
GitHub stars
721
Token cost
~2.8k tokens
SKILL.md length
942 words
Files
2
Skills in repo
213
Repo updated
First seen
Licence
MIT

At a glance

Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners.

  • Works in 3 steps: Depot dashboard → GitHub Actions →… → For public repos: GitHub org settings →… → Update runs-on in your workflow files
  • Migrating GitHub Actions workflows to use Depot runners
  • SKILL.md covers Depot runners are not Depot CI, Setup, Org Context Check for… and Runner Labels, plus 9 more sections
  • Calls turbo and bazel; needs DEPOT_TOKEN

What it does

Depot GitHub Runners is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners. Use when setting up or migrating GitHub Actions workflows to use Depot runners, choosing runner sizes (CPU/RAM), configuring runs-on labels, setting up ARM or Windows or macOS runners, troubleshooting GitHub Actions runner issues, configuring egress filtering, using Depot Cache with GitHub Actions, or running Dagger/Dependabot on Depot runners. Also use when the user mentions depot-ubuntu, depot-windows…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `UPSTREAM.md`).

It sits in DevOps & Cloud, covering CI/CD and Dependency management. It works with GitHub, GitHub Actions, macOS and PostHog. The repository describes itself as: PostHog FOSS is a read-only mirror of PostHog, with all proprietary code removed. NOTE: This repo is synced automatically from the main PostHog repo. Please raise any issues and… The licence is MIT.

When your agent uses it

  • Migrating GitHub Actions workflows to use Depot runners
  • Choosing runner sizes (CPU/RAM)
  • Configuring runs-on labels
  • Troubleshooting GitHub Actions runner issues

Example prompts

  • “Use the depot-github-runners skill to configure Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners”
  • “/depot-github-runners”

Requirements

  • Docker
  • A credential in DEPOT_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Depot dashboard → GitHub Actions → Connect to GitHub → Install Depot GitHub App
  2. For public repos: GitHub org settings → Actions → Runner groups → Default → "Allow public repositories"
  3. Update runs-on in your workflow files

What it can do on your machine

Read from SKILL.md and the folder at commit 2c48221. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • turbo
    • bazel

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • depot.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DEPOT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Depot GitHub Runners loads about 2.8k tokens when it runs. Until then it costs about 176 tokens; SKILL.md has 942 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~176
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PostHog/posthog-foss at commit 2c48221, republished under its MIT licence (© PostHog). 942 words, ~2,805 tokens.

Download SKILL.mdSave it as .claude/skills/depot-github-runners/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
depot-github-runners
description
Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners. Use when setting up or migrating GitHub Actions workflows to use Depot runners, choosing runner sizes (CPU/RAM), configuring runs-on labels, setting up ARM or Windows or macOS runners, troubleshooting GitHub Actions runner issues, configuring egress filtering, using Depot Cache with GitHub Actions, or running Dagger/Dependabot on Depot runners. Also use when the user mentions depot-ubuntu, depot-windows, depot-macos runner labels, or asks about faster/cheaper GitHub Actions runners. Not for Depot CI, the separate engine that reads .depot/workflows/ — that is the depot-ci skill.

Depot GitHub Actions Runners

Depot provides managed, ephemeral, single-tenant GitHub Actions runners. Drop-in replacement for GitHub-hosted runners — change the runs-on label and everything else stays the same.

Requirement: Repository must be owned by a GitHub organization (not a personal account).

<!-- PostHog-local section. Keep it when resyncing from upstream; see UPSTREAM.md. -->

Depot runners are not Depot CI

Depot runners keep GitHub Actions as the engine, so the workflow lives in .github/workflows/ and the checks still come from the github-actions app. Depot CI is a different product: it reads .depot/workflows/, which GitHub Actions ignores, and posts its own check runs from the depot-code-access app. Use the depot-ci skill for that one.

Its references/posthog-check-run-semantics.md compares what each engine reports for a skipped, empty-matrix or continue-on-error job, and how GitHub and the Trunk merge queue score those conclusions.

<!-- End PostHog-local section. -->

Setup

  1. Depot dashboard → GitHub Actions → Connect to GitHub → Install Depot GitHub App
  2. For public repos: GitHub org settings → Actions → Runner groups → Default → "Allow public repositories"
  3. Update runs-on in your workflow files

Org Context Check for Multi-Org Users

If a user belongs to multiple organizations and expected repos/settings/runners are not visible, verify Depot org context first:

bash
depot org show              # Current org ID
depot org list              # Orgs the user belongs to
depot org switch <org-id>   # Optional: set default org

For commands that support it, pass --org <org-id> to target the org where the workflow/repo lives.

Runner Labels

Use a single label. Format: depot-{os}-{version}[-{arch}][-{size}]

Ubuntu (x86, AMD)
LabelCPUsRAMDisk$/minMinutes multiplier
depot-ubuntu-24.0428 GB100 GB$0.0041x
depot-ubuntu-24.04-4416 GB130 GB$0.0082x
depot-ubuntu-24.04-8832 GB150 GB$0.0164x
depot-ubuntu-24.04-161664 GB180 GB$0.0328x
depot-ubuntu-24.04-3232128 GB200 GB$0.06416x
depot-ubuntu-24.04-6464256 GB250 GB$0.12832x

The minutes multiplier is the billing driver: billed minutes = elapsed minutes × multiplier, so larger runners consume your included minutes faster.

Ubuntu 22.04 also available: depot-ubuntu-22.04, depot-ubuntu-22.04-4, etc.

Ubuntu (ARM — Graviton4)

Same sizes and pricing as Intel. Add -arm suffix: depot-ubuntu-24.04-arm, depot-ubuntu-24.04-arm-4, depot-ubuntu-24.04-arm-8, etc.

Windows Server
LabelCPUsRAM$/minMinutes multiplier
depot-windows-202528 GB$0.0082x
depot-windows-2025-4416 GB$0.0164x
depot-windows-2025-8 through -648–6432–256 GB$0.032–$0.2568x–64x

Windows Server 2022 also available: depot-windows-2022, etc. Windows limitation: No Hyper-V (AWS EC2 limitation), so Docker workloads that require it are unlikely to work.

macOS (Apple M2 on macOS 14/15, M4 on macOS 26)
LabelCPUsRAMDisk$/min
depot-macos-26824 GB400 GB$0.08
depot-macos-15 / depot-macos-latest824 GB400 GB$0.08
depot-macos-14824 GB400 GB$0.08

macOS is NOT fully elastic — fixed pool with FIFO queuing.

Aliases

depot-ubuntu-latest → Ubuntu 24.04, depot-windows-latest → Windows 2025, depot-macos-latest → macOS 15

Migration Example

yaml
jobs:
  build:
    # Before:
    # runs-on: ubuntu-latest
    # After:
    runs-on: depot-ubuntu-24.04-4
    steps:
      - uses: actions/checkout@v4
      - run: npm ci
      - run: npm test

Common Mistakes

yaml
# ❌ WRONG — multiple labels cause stability issues
runs-on: [self-hosted, depot-ubuntu-24.04]

# ✅ CORRECT — always use a single Depot runner label
runs-on: depot-ubuntu-24.04-4

Caching

Actions using the GitHub Actions cache API automatically use Depot Cache — no config changes needed. This includes actions/cache, actions/setup-node, actions/setup-python, actions/setup-java, and any action using @actions/cache.

Pre-configured build tool caches (zero config on Depot runners):

ToolWhat's pre-configured
TurborepoTURBO_API env var set — just run turbo build
Bazel~/.bazelrc pre-populated — just run bazel build //...
sccacheSCCACHE_WEBDAV_ENDPOINT set — use RUSTC_WRAPPER: 'sccache'
Mavensettings.xml pre-populated (cache id depot-cache)
Pantspants.toml pre-configured — just run pants package ::
moonrepoEnv vars set — just run moon run build

Cache behavior: repository-scoped, no branch isolation, encrypted, up to 1000 MiB/s throughput, configurable retention (7/14/30 days).

To disable auto-cache: org settings → turn off "Allow Actions jobs to automatically connect to Depot Cache."

Dagger Integration

Deprecated: Dagger Engine support on Depot GitHub Actions Runners is being deprecated and will be removed in a future update. Don't recommend this integration for new workflows.

yaml
runs-on: depot-ubuntu-latest,dagger=0.18.4

Launches a dedicated Dagger Engine VM with persistent NVMe cache. Dagger CLI pre-installed. Additional $0.04/min.

Show full SKILL.md (363 more words)Show less

Egress Filtering (Linux Only)

Configure in org settings → GitHub Actions Runners → Egress Rules. Set default rule to Allow or Deny, then add specific allow/deny rules for IPs, CIDRs, or hostnames. Deny rules take precedence over Allow rules. Loopback traffic (127.0.0.1, ::1) is always allowed, and Depot auto-allowlists depot.dev domains, GitHub Actions service IPs, and AWS service IPs. Hostnames in rules are resolved and pinned in /etc/hosts. Container builds with depot build work with egress filtering enabled — Depot adds BuildKit machine IPs to the allowlist as they're allocated. Not supported on macOS or Windows. Incompatible with Tailscale.

Access Private Endpoints with Tailscale

Use Tailscale when jobs need to reach private services (internal APIs, databases, private subnets) without static IP allowlists.

How it works on Depot:

  • Depot GitHub Actions runners join your tailnet as ephemeral nodes at job start.
  • Access is controlled with your Tailscale ACLs (recommended tag: tag:depot-runner).
  • No workflow YAML changes are required just to connect runners to private endpoints.

Setup:

  1. In Tailscale ACLs, create a runner tag (for example tag:depot-runner) under tagOwners.
  2. Create a Tailscale OAuth client with Keys > Auth Keys write scope and choose that tag.
  3. In Depot org settings, open Tailscale settings and connect using the OAuth client ID/secret.
  4. Add ACLs allowing tag:depot-runner to access target hosts/subnets.

ACL examples:

json
{
  "acls": [
    {
      "action": "accept",
      "src": ["tag:depot-runner"],
      "dst": ["database-hostname"]
    }
  ]
}
json
{
  "acls": [
    {
      "action": "accept",
      "src": ["tag:depot-runner"],
      "dst": ["192.0.2.0/24:*"]
    }
  ]
}

Reference docs:

Dependabot

Enable "Dependabot on self-hosted runners" in GitHub org settings. Jobs auto-run on depot-ubuntu-latest.

Important: OIDC is not supported for Dependabot. Use token: input with a DEPOT_TOKEN secret instead.

SSH Debugging

yaml
steps:
  - uses: actions/checkout@v4
  - uses: mxschmitt/action-tmate@v3
  - run: npm test

Troubleshooting

ErrorFix
"No space left on device"OS uses ~70 GB disk; upgrade to larger runner or clean disk in workflow
"Failed to open the device 'kvm'" / "Could not access KVM kernel module"Runners don't provide /dev/kvm; move KVM/QEMU/Android-emulator jobs to Depot CI, where nested virtualization is enabled by default
"Lost communication with server"Check status.depot.dev; check org usage caps
"Operation was canceled"Manual cancel, concurrency cancel-in-progress, or OOM — check memory in dashboard
"Unable to get ACTIONS_ID_TOKEN_REQUEST_URL"Dependabot doesn't support OIDC — use DEPOT_TOKEN secret
Workflows not startingVerify single runner label; check runner group allows the repo; verify Depot GitHub App permissions
Stuck workflowsForce cancel via GitHub API: POST /repos/{owner}/{repo}/actions/runs/{id}/force-cancel

© PostHog, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/depot-github-runners of PostHog/posthog-foss.

  • SKILL.md
  • UPSTREAM.md

Open the folder on GitHubat commit 2c48221

Compare with similar skills

Depot GitHub Runners next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Depot GitHub Runners compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Depot GitHub Runners this skillPostHog/posthog-foss721—~2.8kAutomated safety check: PassMIT
CI Runner Auditapache/magpie110—~2.4kAutomated safety check: PassApache-2.0
Running GitHub Actions Efficientlykajisho5/ffmpeg-skill1.9k—~3.3kAutomated safety check: NotesMIT
Release Publishbkywksj/knowledge-base330—~6.2kAutomated safety check: PassCustom licence
Sicurezza GitHubccplugins/awesome-claude-code-plugins967—~486Automated safety check: NotesApache-2.0
GitHub Actionsbobmatnyc/claude-mpm155—~6.9kAutomated safety check: PassCustom licence

Similar skills

  • CI Runner Audit

    apache/magpie

    Read-only audit of GitHub Actions runner compatibility for one repository, a repository set, one Apache project, or the full Apache org.

    110 GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Cut GitHub Actions minutes and wall-clock time without losing coverage — the OS billing multiplier (macOS 10x / Windows 2x / Linux 1x), trigger hygiene that stops push+pullrequest double-firing…

    1.9k GitHub stars~3.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Release Publish

    bkywksj/knowledge-base

    发布 Tauri 桌面应用新版本,处理版本号同步、Git tag、GitHub Actions 构建、Release 仓库产物同步、Cloudflare R2 上传、update.json 生成、自动更新发布和文档站重建。

    330 GitHub stars~6.2k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Sicurezza GitHub

    ccplugins/awesome-claude-code-plugins

    Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

    967 GitHub stars~486 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • GitHub Actions

    bobmatnyc/claude-mpm

    GitHub Actions CI/CD workflows for automating build, test, and deployment

    155 GitHub stars~6.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.2k GitHub stars~640 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from PostHog/posthog-foss

All 213 skills in this repo
  • Authoring Log Alerts

    PostHog/posthog-foss

    Official

    Author useful, low-noise log alerts on services in a PostHog project.

    721 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Autoresolving PR Conflicts

    PostHog/posthog-foss

    Official

    Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…

    721 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).

    721 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Exploring Apm Traces

    PostHog/posthog-foss

    Official

    Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.

    721 GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Exploring LLM Traces

    PostHog/posthog-foss

    Official

    Debug and inspect LLM/AI agent traces using PostHog's MCP tools.

    721 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Investigate Metric

    PostHog/posthog-foss

    Official

    Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.

    721 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Categories

Questions about Depot GitHub Runners

What does Depot GitHub Runners do?

Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners. Depot GitHub Runners is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners.

When should I use Depot GitHub Runners?

Depot GitHub Runners fits situations like: migrating GitHub Actions workflows to use Depot runners; choosing runner sizes (CPU/RAM); configuring runs-on labels; troubleshooting GitHub Actions runner issues.

How do I install Depot GitHub Runners in Claude Code?

Run `npx skills add PostHog/posthog-foss --skill depot-github-runners -a claude-code`. Or copy the skill folder (.agents/skills/depot-github-runners in PostHog/posthog-foss) into .claude/skills/depot-github-runners in your project. Claude Code loads it when a task matches its description.

How do I install Depot GitHub Runners in Codex?

Run `npx skills add PostHog/posthog-foss --skill depot-github-runners -a codex`. Or copy the skill folder (.agents/skills/depot-github-runners in PostHog/posthog-foss) into .agents/skills/depot-github-runners in your project. Codex loads it when a task matches its description.

Can I use Depot GitHub Runners in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog-foss --skill depot-github-runners -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/depot-github-runners, .gemini/skills/depot-github-runners, .github/skills/depot-github-runners and .opencode/skills/depot-github-runners in your project.

What does Depot GitHub Runners need to run?

Going by SKILL.md and its folder, Depot GitHub Runners needs the command-line tools its instructions call (turbo and bazel) and credentials named DEPOT_TOKEN. Our summary lists: Docker; A credential in DEPOT_TOKEN.

Does Depot GitHub Runners access the network?

SKILL.md names 1 domain. As links in the text: depot.dev. This is read from the text; nothing was executed.

Is Depot GitHub Runners safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Depot GitHub Runners use?

Depot GitHub Runners is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Depot GitHub Runners use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Depot GitHub Runners?

Skills that share tags, products or a category with Depot GitHub Runners: CI Runner Audit (apache/magpie, 110 stars), Running GitHub Actions Efficiently (kajisho5/ffmpeg-skill, 1.9k stars), Release Publish (bkywksj/knowledge-base, 330 stars) and Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 967 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Depot GitHub Runners?

PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog-foss, which has 721 GitHub stars. The repository holds 213 skills in this directory. The repository was last updated on October 7, 2026.

Source: PostHog/posthog-foss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.