A GitHub-hosted runner lives in GitHub 29 's cloud and cannot reach the LocalStack 63,725 on your machine. A self-hosted runner there can (github.com/actions/runner (https://github.com/actions/runner 6,293 ), MIT, 2.337.0): register it with ./config.sh --url <repository URL> --token <token>, start ./run.sh, and select it with runs-on: self-hosted. It needs only outbound HTTPS.
Not run here, deliberately: GitHub's security guide says self-hosted runners "should almost never be used for public repositories" like booknest-infra, since any pull request could run code on your machine, here with LocalStack's Docker 514 socket, which is root access. But LocalStack is just an image, and a hosted job can run images as service containers: each run gets a clean LocalStack, nothing of yours is exposed, and standard hosted runners are free for public repositories.