Builds share a source address with the runner, and nothing limits their egress.
On bay1 the OUTPUT policy accepts everything and has no runner-specific rules; there are no loopback-only TCP listeners, so a build reaches ports 22, 80, 443 and 2222 plus the internet. Under pasta a build's connections to 169.254.1.2 most likely arrive from 127.0.0.1, the address the runner polls from (-remote git@127.0.0.1, deploy/gitbay-runner.override.conf:78). The SSH auth limiter counts failures per IP (internal/sshd/ratelimit.go:86).
Suspected impact: an untrusted build that fails ten SSH logins a minute throttles the runner's own polling and stalls CI. Not yet tested.
- Test: a throwaway build on a scratch repository failing auth in a loop while the runner polls.
- Separate the runner's source address from its builds' (runner reaches the daemon on the public address, or builds get
GITBAY_SSHpointed at gitbay.org). - Decide an egress policy for untrusted builds and document it in the Threat-Model and CI wiki pages.
referenced in commit 7a6343d02d by cmc: wiki: architecture and security pages
2026-09-28 04:30 UTC