Rendered from docs/process/decisions/0013-self-hosted-eligibility-in-ci-is-decided-by-the-event-alone-and-a-push-to-any-branch-is-eligible.md in the Headwater corpus. Every document on this half of the site is typed by the taxonomy the descriptor names: corpus.json.

Self-hosted eligibility in CI is decided by the event alone, and a push to any branch is eligible

Context

Before this record, the reasons lived in comments of .github/workflows/ci.yml on 2026-09-27. The comments were header rule 1 (lines 32 to 37) and the comment on on: (lines 81 to 84). Two triggers, one verdict states the design as a whole and holds the measurements. This record holds the decision and cites that evaluation for the evidence.

A pull request from a fork runs the fork's own copy of ci.yml. The fork can delete, invert or replace any condition in that copy. So no condition in this file can keep a fork off the self-hosted runner.

Decision

The event decides. The runs-on expression of engine and of headwater reads github.event_name to decide whether the job may run on the self-hosted pool. The runs-on of route is the literal ubuntu-latest (HW-PD-0018). It reads no other field for that choice. It never reads which repository opened a pull request, or any field that the author of a pull request can change.

Every branch. on.push.branches is ['**', '!gh-readonly-queue/**'] and not [main]. The one exclusion is the merge queue's own branches, which run under merge_group instead (HW-PD-0020). A person with commit access writes each push to a feature branch, and nobody reads it yet. That is the case the self-hosted runner exists to make fast. So a push is eligible on every branch.

The router cannot grant. The router of HW-PD-0018 can send an eligible job to a hosted runner. It never makes a job eligible.

Consequences

A pull request always runs on a hosted runner. A push runs on the self-hosted pool only when CI_RUNNER names it (HW-PD-0016) and the pool has space. Since HW-PD-0020, a merge_group run is eligible in the same way as a push, because only a person with write access can queue a pull request.

A runs-on that reads a field of a pull request is a defect, even when it looks safer. A fork removes that condition in its own copy, so the condition protects nothing and hides where the boundary is (HW-PD-0014).

This record reopens if GitHub starts to run the base repository's copy of a workflow for a pull request from a fork.