Self-hosted runners (AWS) are only available on the Enterprise tier. Contact sales to learn more about upgrading.

Benefits of AWS Runner
AWS Runners let you run Ona environments inside your AWS account with enterprise‑grade controls. Key benefits include:- Direct connectivity using your own Network Load Balancer with your domain and SSL/TLS certificate
- AI agent integration for accelerated development workflows (Enterprise tier)
- Private connectivity to the management plane via AWS PrivateLink (no public internet traversal)
- Fine‑grained IAM with permission boundaries to meet enterprise security requirements
- HTTP proxy support for environments behind corporate firewalls
- Custom CA certificate support for enterprise CAs and certificate chains
The Enterprise Runner is exclusively available to customers on the Enterprise tier. If you’re an Enterprise customer, contact your Ona account manager for more information.
Key Features
- Ona AI agent integration - Enhanced development workflows with AI-powered assistance
- Direct connectivity - Bypasses central gateways by using your own Network Load Balancer, secured with your custom domain and SSL/TLS certificate
- Private VPC endpoints - Connect to the management plane via AWS PrivateLink for enhanced security without public internet traversal
- Enhanced security - Fine-grained IAM policies with permission boundaries for enterprise security requirements
- HTTP proxy support - Custom HTTP proxy configuration for environments behind corporate firewalls
- Custom CA certificate support - Support for enterprise certificate authorities and custom certificate chains

Prerequisites
Before deploying your Enterprise AWS Runner, ensure you have:- AWS Account with elevated permissions for enterprise features
- Capacity Planning - Follow our Capacity Planning guide to determine your infrastructure requirements
-
AMI Access - If your organization restricts AMI usage, allowlist the AMIs runners and environments run on
For more details, review our AMI Requirements guideAMI Name Owner Account ID Owner Purpose bottlerocket-aws-ecs-1-x86_64
149721548608
Amazon Runner service gitpod/images/gitpod-next/ec2-runner-ami-*
995913728426
Gitpod Development environments - Domain Name that you control with DNS modification capabilities
-
SSL/TLS Certificate provisioned in AWS Certificate Manager (ACM). Your SSL certificate must include both Subject Alternative Names (SANs):
yourdomain.com
(root domain)*.yourdomain.com
(wildcard subdomain)
Network Requirements
The Enterprise Runner requires a custom VPC with specific networking setup for enhanced security and direct connectivity.
Next Steps
- Setup - Deploy your AWS Runner
- Capacity Planning - Plan your infrastructure needs
- Access Requirements - Configure network access