Runners and Commands

The Runner, the Job Container and the Workflow Commands Protocol

A runner is a machine running the open-source runner application (actions/runner (https://github.com/actions/runner 6,293 ), a .NET program, 2.337.0 here), which polls GitHub 29 over outbound HTTPS for jobs. A GitHub-hosted runner is a fresh virtual machine per job; for public repositories a standard Linux one has 4 CPUs, 16 GB of RAM and a 14 GB SSD (private: 2 CPUs, 8 GB). The job log shows it:

Reading the first job's log without timestamps and colorsShell
gh run view 36127936652 --job 108048302011 --log | cut -f3 \
  | sed 's/^[^ ]* //; s/\x1b\[[0-9;]*m//g'
Output
Current runner version: '2.337.0'
...
Image: ubuntu-24.04
Version: 20260920.314.1
...
echo "::add-mask::shelf-key-1234"
echo "The shelf key is shelf-key-1234"
...
shell: /usr/bin/bash -e {0}
##[endgroup]
Runner GitHub Actions 1000000001: ubuntu24 20260920.314.1, 4 CPUs
Workspace /home/runner/work/booknest/booknest, commit 4943462
The shelf key is ***
##[notice]Hello from job on-the-runner

Each run: block becomes a script run with bash -e. Scripts talk back through workflow commands, stdout lines shaped ::command key=value::message that the runner parses as they stream: ::notice::, ::warning:: and ::error:: become annotations, ::group:: folds lines, and ::add-mask:: prints a value as *** from then on. The echoed script above still shows the value, so never write a real secret into a workflow. Data that outlives a step goes through the files named by $GITHUB_OUTPUT, $GITHUB_ENV, $GITHUB_PATH and $GITHUB_STEP_SUMMARY.

The second job ran in a job container. Its log shows the runner creating a private network, pulling node:24-alpine, and running docker create with the entrypoint replaced by tail -f /dev/null, so the container idles, and with its work directory mounted at /__w. Each step then runs through docker exec, and the container and network are removed at the end. Service containers, such as the PostgreSQL 1,289 for BookNest's tests in Matrices and Caching, join the same network.