Intermittent failures in runner group and runner-related permissions pages

lowGitHubAug 18, 2026 07:40Duration: 4h 2m
apiauthenticationsecuritycertificate
Security IncidentCertificate IssueAuthentication IssueAPI Issue

Summary

On August 18, 2026, between 05:02 UTC and 11:30 UTC, customers were unable to view or manage Actions Runners and Runner Groups through the GitHub UI and API. <br /><br />The issue was caused by failures in backend requests reading runner and runner group data. The failures were caused by an expired authentication certificate unique to this service. The certificate had been rotated in KeyVault, but a step to enable use at runtime had been paused to prevent recurrence of previous incidents trigger

Impact

minor

Timeline

Aug 18, 2026 07:40

[investigating] We are investigating reports of impacted performance for some GitHub services.

via statuspage
+0m
Aug 18, 2026 07:40

[monitoring] We are investigating reports of failure to load runner groups and runner-related permissions for customers using larger runners.

via statuspage
+3h 1m
Aug 18, 2026 10:41

[monitoring] We have identified the source of a communication issue between Actions services and are working toward mitigation. Customers may experience failure to load runner groups and runner-related permissions issues when using Larger Runners.

via statuspage
+42m
Aug 18, 2026 11:24

[monitoring] We have applied a mitigation and are seeing recovery signals. We will continue monitoring recovery and providing updates.

via statuspage
+19m
Aug 18, 2026 11:42

[resolved] This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available.

via statuspage
+0m
Aug 18, 2026 11:42

[resolved] On February 18, 2026, between 05:02 UTC and 11:30 UTC, customers were unable to view or manage Actions Runners and Runner Groups through the GitHub UI and API. <br /><br />The issue was caused by failures in backend requests reading runner and runner group data. The failures were caused by an expired authentication certificate unique to this service. The certificate had been rotated in KeyVault, but a step to enable use at runtime had been paused to prevent recurrence of previous incidents triggered by this operation. <br /><br />The impact was mitigated by completing the enablement of the new certificate in the backend system. We have added additional monitoring to this and other certificates. This service is also in the process of being replaced as part of our availability and scale work, bringing this authentication path and secret management in line with patterns across all GitHub services.

via statuspage
+0m
Aug 18, 2026 11:42

[resolved] On August 18, 2026, between 05:02 UTC and 11:30 UTC, customers were unable to view or manage Actions Runners and Runner Groups through the GitHub UI and API. <br /><br />The issue was caused by failures in backend requests reading runner and runner group data. The failures were caused by an expired authentication certificate unique to this service. The certificate had been rotated in KeyVault, but a step to enable use at runtime had been paused to prevent recurrence of previous incidents triggered by this operation. <br /><br />The impact was mitigated by completing the enablement of the new certificate in the backend system. We have added additional monitoring to this and other certificates. This service is also in the process of being replaced as part of our availability and scale work, bringing this authentication path and secret management in line with patterns across all GitHub services.

via statuspage

Lessons Learned

GitHub has experienced 148 incidents in the past year. This frequency suggests systemic reliability challenges that may warrant additional monitoring.

📊Incidents related to api, authentication, security, certificate have occurred 1078 times across all providers in the past year. This is one of the most common failure categories in cloud infrastructure.

💡This incident is categorized as: Security Incident, Certificate Issue, Authentication Issue, API Issue. Consider implementing preventive measures specific to this failure category.