Getting started
Run GitHub Actions macOS jobs on XenoCI runners: credits, GitHub connection, isolation and limits.
XenoCI provides GitHub Actions-compatible Apple Silicon (M4) macOS runners. Every job gets a fresh macOS VM, deleted when the job ends. Usage is paid for in credits.
1. Credits and pricing
1 credit is 1 minute of a macOS runner. Run time is charged per second with no minimum. xenoci-macos is 4 vCPU · 8 GiB at 1 credit per minute.
- Free credits — every account gets 100 credits, refilled every month. Unused credits do not roll over. Free credits are granted once you connect a GitHub account at least 30 days old, once per GitHub account and once per XenoCI account.
- Extra credits — bought as credit packs in the console: 100 credits for KRW 9,900, 300 credits (+30 bonus) for KRW 29,900 and 500 credits (+100 bonus) for KRW 49,900. Purchased credits never expire.
- Order of use — free credits always go first. Extra credits are used only after they run out, and only if you turn on Use extra credits. It is off by default; while it is off, new jobs wait and nothing extra is charged.
- Refunds — Purchased extra credits are refunded in full if you ask within 7 days of payment and have used none of them. Otherwise, unused purchased credits are refunded on request to support, minus 10% of the payment for payment and processing fees. Credits already used, the monthly free credits, pack bonuses and operator adjustments are not refundable. If a job fails because of a problem on our side, we return the credits it used once we have checked.
The console usage screen shows daily usage (Korea time) by repository and label, with CSV export. It is also where you set a monthly usage cap, a concurrency ceiling and pause new job assignment. Limits only block new jobs; jobs already running finish.
2. Connect GitHub and switch a workflow
- Click Connect GitHub in the console and GitHub opens in a new tab. Install the XenoCI GitHub App on your personal account or organization and choose the repositories to build. Installing on an organization may need the organization owner’s approval.
- In the workflow file, change the macOS job’s
runs-ontoxenoci-macos. - Push, and GitHub hands that job to XenoCI. A single-use runner is registered for each job and removed with the VM when it ends. Your other jobs keep running on GitHub as before.
Change which repositories are included at any time on GitHub’s App installation page. When you add a repository on GitHub it appears in the console shortly after (you need admin access to the repository). Code is fetched by the workflow’s checkout step, as usual.
name: build
on: [push, workflow_dispatch]
jobs:
ios:
runs-on: xenoci-macos
steps:
- uses: actions/checkout@v4
- run: xcodebuild -scheme App -destination 'platform=iOS Simulator,name=iPhone 16' testComplete .github/workflows/build.yml (use your own scheme name)
3. Secrets, OIDC and artifacts
- Repository and organization secrets — values stored in GitHub Actions secrets are injected into the job by GitHub. XenoCI runners receive
secrets.*exactly like GitHub-hosted runners. - OIDC cloud sign-in — deploying to AWS, GCP, Azure and others without long-lived tokens needs OIDC and
permissions: id-token: write. XenoCI passes the OIDC token issued by GitHub through unchanged. - Artifacts and caches — data uploaded with
actions/upload-artifactandactions/cacheis stored on GitHub. The XenoCI macOS VM is deleted when the job ends.
4. Isolation and network
Every job gets a new VM that is deleted when the job ends. Runners cannot reach the internet directly; they reach only allowed domains, through a proxy. GitHub, npm, PyPI, crates.io, the Go proxy, Maven, Docker Hub, Ubuntu and Debian packages and Apple developer domains are allowed by default; add private registries as allowed domains in the console settings.
5. Limitations
- Hardware:
xenoci-macos— 4 vCPU · 8 GiB · 1 credit per minute. - Guest: macOS 26.6.2 · Xcode 26.2, 26.3, 26.4.1, 26.5, 26.6, 27.0. The default Xcode is 27.0.
- Time limit: a job runs for at most 60 minutes. A job past its limit is stopped and only the time it actually ran is charged.
- Uses other than building and testing — crypto mining, spam, scanning and the like — are prohibited, and CI access is suspended when detected.