First of the three merge requests the runner isolation design sequences, and the one that is independently valuable: no new dependency, testable today.
cmd.Env = append(os.Environ(), …) handed every build step the runner service's
entire environment. A step now gets a constructed one: PATH, HOME, LANG,
CI, the GITBAY_* variables, and its secrets — which the server sends only for
a trusted build, so a fork's merge request still gets none.
HOME is the workspace rather than the runner's home. That is a change the
design does not call for and I think it should: tools read credentials out of
dotfiles — .netrc, .npmrc, .gitconfig — and a build has no business finding
the runner's. It also puts a build's caches in the workspace, where they go away
with it.
PATH is the one value carried over, with a fallback: without it a step cannot
find the tools the host was provisioned with.
This does not close the key-theft path — a step can still read the runner's SSH key off the disk by path. That is what the container split in the second merge request is for; this one narrows what a step is handed.
TestStepEnv* set variables on the runner and assert they do not reach a step,
check the constructed values, the secret passthrough, and the PATH fallback. The
existing CI e2e suite passes against the constructed environment.
Stacked on !288.
Ref #144
retargeted from bookmarks-146 to main: !288 merged
2026-09-06 20:03 UTC