Untrusted builds share a writable HOME with trusted builds of the same repository.
buildHomeFor(r.workdir, j.Repo) (cmd/gitbay-runner/main.go:325) keys the home on the repository alone, and the container mounts it read-write (cmd/gitbay-runner/isolate.go:160). The bay1 runner runs with -untrusted, so a fork MR build can write to the Go module and build caches, or plant dotfiles, that the next trusted krz/gitbay build uses.
No secrets are attached to krz/gitbay or cmc/cleberg.net today, so the current impact is trusted-build integrity. Any repository that adds a secret turns it into disclosure.
- Untrusted builds get a disposable home, removed with the workspace.
- The claim payload carries the trust classification explicitly; absence of secrets is not the signal.
- Persistent caches only within one trust domain; nothing written by an untrusted build is reused by a trusted one.
- Discard the existing shared homes on bay1 when this deploys.
referenced in commit 7a6343d02d by cmc: wiki: architecture and security pages
2026-09-28 04:30 UTC