KNOWLEDGE BASE

How to Diagnose a GitLab Runner Job Stuck in Pending

A Pending job often indicates no eligible Runner, exhausted capacity, tag or protection rules, or Runner connectivity problems. Identify the blocking layer before changing registration.

01

Pending and running failures are different

A Pending job has not been accepted by an eligible Runner. A job stuck in Running should instead be assessed at the executor, build environment and job-command layers.

The UI can indicate a tag or eligibility problem, but Runner and GitLab evidence should be correlated before acting.

02

Record Runner service state first

Inspect service and registration status on the Runner host without changing it. Sanitize URLs and identifiers before sharing outputs.

sudo systemctl status gitlab-runner --no-pager
sudo gitlab-runner list
sudo gitlab-runner verify
  • Is the service active or repeatedly restarting?
  • Is the Runner registered to the expected GitLab URL?
  • Can verify establish connectivity?
  • Is the Runner paused or offline in GitLab?
03

Tags and protection rules

A job is not accepted when its tags do not match the Runner. Untagged-job handling, protected Runners and protected branches also affect eligibility.

Removing protection may appear to fix the queue while allowing untrusted code to execute on a production-privileged Runner.

  • The tags declared by the job
  • Run untagged jobs setting
  • Protected Runner and branch relationship
  • Project, group or instance scope
  • Projects to which the Runner is locked
04

Capacity and executor layer

An online Runner can still have no worker capacity because of concurrency limits or executor startup failures.

Measure queue depth, job duration, CPU, memory, disk and concurrency before increasing capacity.

  • Global concurrent and Runner limits
  • Long-running or blocked jobs
  • Docker image-pull and disk failures
  • Kubernetes pod scheduling
  • Shell executor permissions and working directory
05

Network, TLS and clock synchronization

A Runner that cannot reach the GitLab API may remain offline or fail to request jobs. Check proxy, DNS, TLS chain and system time.

Disabling certificate verification is not a durable solution; distribute the internal CA correctly.

  • Can the Runner host resolve the GitLab URL?
  • Is the 443/TCP path blocked?
  • Is the TLS chain trusted?
  • Are system clocks synchronized?
  • Does the reverse proxy expose the correct external URL?
06

When should configuration changes be managed?

Token rotation, re-registration, concurrency changes, executor migration and production permissions can affect existing pipelines and security boundaries.

Atlas Infrastructure examines eligibility, capacity, executor logs and access design together before implementing a controlled correction.

FREQUENTLY ASKED QUESTIONS

Common questions about GitLab

Why is a job Pending when the Runner is online?

Tags, protected branches, untagged-job handling, scope or concurrency rules can make an online Runner ineligible.

Will re-registering the Runner fix it?

It may be required for a token or connectivity issue, but doing so without evidence can change identity, tags and security scope.

Is it safe to increase concurrency?

Increasing it without measuring host and executor capacity can exhaust resources and make more jobs fail simultaneously.

How to Diagnose a GitLab Runner Job Stuck in Pending | Atlas Infrastructure