Requires Enterprise plan. Contact sales for access.
- source code and execution to stay in your AWS network
- tighter control over networking, IAM, and regional placement
- integration with existing platform, compliance, or network controls

What the runner includes
An AWS runner gives Ona an execution layer inside your VPC. The deployment includes:- a runner orchestrator running on AWS-managed infrastructure you control
- environment provisioning for development environments and agent runs
- repository access and secret handling inside your AWS boundary
- network and IAM integration with the rest of your AWS estate
Plan before you deploy
Before setup, confirm these prerequisites:- AWS account permissions for deploying the CloudFormation stacks and related IAM resources
- Capacity planning for the environment sizes and concurrency your team needs
- AMI allowlisting if your organization restricts AMI usage
- A domain and certificate for the runner endpoints
- A network posture for public access, private access, or private endpoints
| AMI Name | Owner Account ID | Purpose |
|---|---|---|
bottlerocket-aws-ecs-1-x86_64 | 149721548608 | Runner service |
gitpod/images/gitpod-next/ec2-runner-ami-* | 995913728426 | Environments |
Common rollout path
Teams usually follow this sequence:- review capacity planning
- work through setup
- configure repository access
- review detailed access requirements and VPC endpoints if the network posture is strict
- configure environment classes and monitoring