Actions / Documentation

Labels, capacity and commands

The look-up page. Everything a device honors — labels, capacity flags, environment variables, network policy, commands and the local files it keeps — with the defaults the beta actually ships.

← All documentation

Runner labels

A label names a size and an operating system. Each size allocates that many CPUs and that many GiB of memory to the job. Use the smallest one that fits; a larger label does not run the job faster, it reserves more of your machine.

LabelCPUsJob memory
tbench-2vcpu-ubuntu-240422048 MiB
tbench-4vcpu-ubuntu-240444096 MiB
tbench-8vcpu-ubuntu-240488192 MiB
tbench-16vcpu-ubuntu-24041616384 MiB

Ubuntu 24.04 x64 is the only qualified image; there is no 22.04 label. Windows job images, macOS/ARM and GPU jobs are not qualified.

Device capacity

A device advertises the largest label its own caps and Docker allocation allow. A job is never silently placed above the device’s opted-in capacity — an oversized assignment is refused, not reduced.

  • Defaults are TBENCH_MAX_CPUS=2 and TBENCH_MAX_MEMORY_MB=4096. The memory figure includes the 128 MiB egress proxy.
  • The proxy has its own 0.25 CPU ceiling — small, bounded overhead, not part of the job’s advertised CPU class.
  • The effective offer is the smaller of your flags and the host. The default tbench-2vcpu-ubuntu-2404 fits a two-CPU, four-GiB device.

Docker Engine 28 or newer is required for the qualified isolated network mode. The engine must report an x86-64 Linux container type, which on Windows means Docker Desktop in Linux-container mode.

Environment variables

Device environment variables
NamePurpose
TBENCH_MAX_CPUSUpper bound on job CPUs this device will offer. Default 2; range 1–16.
TBENCH_MAX_MEMORY_MBDevice memory budget for jobs, in MiB. Default 4096; range 1024–65536.
TBENCH_EGRESS_PROFILENetwork policy. Default github-only; package-registries adds only the npm and PyPI registries.
TBENCH_RUNNER_IMAGEOverride the pinned runner image tag (advanced; the preflight still verifies the image OS).
TBENCH_PROXY_IMAGEOverride the pinned egress proxy image tag (advanced).

Caps are clamped to the host: you cannot advertise more CPUs or memory than Docker will actually give the container.

Egress profiles

ProfileAllowed
github-only (default)GitHub only.
package-registriesGitHub plus registry.npmjs.org, pypi.org and files.pythonhosted.org.

HTTPS CONNECT on port 443 is required. All DNS answers must be globally routable; the connection uses the validated address without a second lookup. Private, LAN and cloud-metadata addresses and arbitrary hosts remain denied.

Worker commands

The launcher is tbench-worker. After enrollment its installer prints the path where it was placed; it does not change your PATH for you.

Worker commands
NamePurpose
tbench-worker enrollEnroll this device with a single-use token, by hidden prompt or --enrollment-file. Refuses to run twice.
tbench-worker checkRun the local diagnostics: device caps, the Ubuntu 24.04 image, Docker version, and broker enrollment.
tbench-worker serveTake jobs for a bounded session. Defaults: tbench-worker serve --max-hours 8 --max-jobs 10.
tbench-worker runClaim and run a single job once, then exit.
tbench-worker recover <request-id>After a crash, check owned local resources and GitHub, then clear a request that is safe to clear.
tbench-worker stopAsk a serving worker to stop within one poll interval. Enrollment and stop never claim work.

A bounded session serves for up to eight hours or ten jobs, whichever comes first, and polls for work. It installs no background service and starts no paid cloud fallback.

Files a device keeps

Local worker files
NamePurpose
.worker-state.jsonThe device’s revocable enrollment bearer and enrolled repository set. Written with private permissions.
.worker.lockHeld while a worker runs, so only one process on the device owns jobs at a time.
.worker-journalThe exact containers, networks and runner a request created, so recovery removes only those.
.worker-stopPresent when a bounded session has been asked to stop.
.upgrade-in-progressRetained after an interrupted upgrade; blocks claiming until a reviewed reinstall finishes.

None of these hold a GitHub credential. If a run is interrupted, recovery reads the journal to remove only what that request owned.