TRUSTED BY ENGINEERING TEAMS · SELF-HOSTED · ELv2 LICENSE
RunRight profiles every CI job, recommends right-sized runners across AWS, GCP, and Azure, tracks carbon footprint, and enforces cost policies. SSO, RBAC, and an AI cost assistant are built in.
PROFILE → OPTIMIZE → ENFORCE
Install RunRight →RunRight continuously profiles real usage and recommends the lowest-cost runner that still satisfies your workload requirements.
RunRight samples CPU, memory, disk I/O, and thread usage throughout every workflow run to build an accurate workload profile.
Track utilization, waste, cost, and savings trends over time as workloads evolve.
Receive runner recommendations, enforce policy limits, and route alerts automatically when thresholds are crossed.
ACTIONABLE OUTPUT
Not another dashboard. Not another billing report.
RunRight converts workload telemetry into a specific infrastructure decision: keep your current runner or switch to a lower-cost alternative.
| RANK | INSTANCE | VCPU | RAM | COST/MIN | SAVINGS |
|---|---|---|---|---|---|
| BEST FIT | t4g.small | 2 | 2 GB | $0.0042 | -78% |
| 2 | t3a.small | 2 | 2 GB | $0.0047 | -76% |
| 3 | t3.small | 2 | 2 GB | $0.0052 | -73% |
Measure CO₂ emissions per job. Track sustainability KPIs and report on green CI initiatives.
300+ instance types across all major clouds, including ARM (Graviton, Ampere).
Route event and threshold alerts to Slack, Teams, email, or webhooks by team or service.
Set max cost/hour guardrails globally, per repository, or per job and enforce them in CI.
Five built-in roles, custom role creation, and full audit logging for every action across your team.
Ask your job history anything. Runs on your own Ollama or OpenAI-compatible endpoint. No SaaS required.
POLICY + ALERTING
Most alerting systems create noise. RunRight only notifies teams when something requires action.
Fewer ignored alerts. Faster remediation. Controlled CI spend.
| AREA | DETAIL |
|---|---|
| GUARDRAILS | Policy scope precedence: job > repository > global. |
| THRESHOLDS | Cost threshold violations, waste threshold breaches, and savings regressions trigger only when intervention is needed. |
| ROUTING | Route alerts to Slack, Teams, email, or webhooks based on repository ownership. The right team gets the right signal automatically. |
| POLICY EVENTS | Policy violations and scheduled daily summaries keep teams informed. Failed deliveries are retried automatically with backoff. |
TEAM CONTROLS
Assign roles to control exactly who can view and change what. No external identity provider required.
Five built-in roles. Custom role creation. Full SSO integration. Every action logged.
| ROLE | WHAT THEY CAN DO | TYPE |
|---|---|---|
| Owner | Unrestricted access: all configuration, all data | BUILT-IN |
| All write actions: policies, alerts, jobs, ownership, teams, API keys, and reports | BUILT-IN | |
| Billing | View reports and audit logs. No policy or alert writes. | BUILT-IN |
| Snooze, archive, and delete job data. No system config access. | BUILT-IN | |
| Viewer | Read-only access across all dashboards. No writes. | BUILT-IN |
| Custom… | Create roles with any combination of the eight permission scopes from the dashboard. No restart required. | CUSTOM |
Roles are assigned when SSO users first log in. Supports Google, GitHub, Azure AD, Okta, and any OIDC or SAML provider.
Mix and match from eight permission scopes (policies, alerts, jobs, ownership, team, API keys, reports, and audit) to create roles that fit your org.
Every create, update, and delete is logged with actor, timestamp, and changed fields. Granular per-rule tracking for alert configuration changes.
Traditional observability and cloud-cost platforms focus on attribution. RunRight focuses on action.
Runner sizes are usually chosen once and forgotten. Repositories change. Workloads evolve. Infrastructure stays the same. The result is wasted CPU, wasted memory, and rising CI costs without ownership.
Cost governance is the outcome. Instead of just showing where money went, RunRight tells you what runner to use next, enforces spending policies, and alerts teams when efficiency declines.
RunRight combines live workload profiling, AWS and GCP instance matching, estimated savings, policy enforcement, and team-routed alerts into one continuous loop.
GitHub Actions, GitLab CI, Jenkins, CircleCI, Bitbucket Pipelines, Kubernetes runners, self-hosted VMs, and custom build environments. Wherever your workloads run, RunRight can profile them.
Reads vCPU count and total memory from the OS, then matches against the catalog within a 2 GiB tolerance. Works on any CI platform: GitHub Actions, self-hosted EC2, GCP VMs, Azure VMs, and more.
Reads cgroup v2 (cpu.max, memory.max) or cgroup v1 equivalents. Reflects your pod's actual CPU quota and memory limit.
# K8s Downward API override (optional)
env:
- name: RUNRIGHT_VCPUS
valueFrom:
resourceFieldRef:
resource: limits.cpu
- name: RUNRIGHT_MEMORY_GIB
valueFrom:
resourceFieldRef:
resource: limits.memory
divisor: 1Gi
Skip auto-detection with two env vars. Works for Azure VMs, ARM instances, on-prem, or any environment where OS-level resource counts are unreliable.
RUNRIGHT_VCPUS=4 RUNRIGHT_MEMORY_GIB=16
INTEGRATIONS
GitHub Actions, GitLab CI, Jenkins, CircleCI, Bitbucket Pipelines, Kubernetes runners, and any platform that can run a shell command.
SAVINGS CALCULATOR
Based on typical CI job utilisation (p95 CPU 30%, p95 RAM 40%).
CURRENT / MO
—
SAVINGS / MO
—
AFTER RUNRIGHT / MO
—
AI COST ASSISTANT
The built-in AI assistant connects to your actual job history, repository ownership, and cost data, answering questions with context from your own telemetry.
No external SaaS. Runs on your infrastructure with Ollama or any OpenAI-compatible endpoint.
Based on the last 30 days, here are the top three repositories by CI cost with high waste scores:
Switching all three saves an estimated $1,240/month. Want me to draft the policy rules for each?
ENTERPRISE READY
Self-hosted on your infrastructure. No data leaves your network. SOC 2 compliant architecture.
Google, GitHub, Azure AD, Okta, and any OIDC provider.
Immutable record of every configuration change and access event.
Architecture designed for compliance. RBAC, encryption, and access controls.
Your data never leaves your infrastructure. No SaaS dependency.
PRICING
No seats. No usage limits. No SaaS lock-in. Your telemetry stays on your infrastructure.
See full pricing →START CONTROLLING CI COSTS
Profile workloads. Find waste. Enforce policies. Route alerts.
Open Install Guide →