runner: construct the step environment instead of inheriting it !289

merged merged by cmc on 2026-09-06 20:03 UTC · krz/gitbay:runner-env-144 into main

Discussion

cmc

First of the three merge requests the runner isolation design sequences, and the one that is independently valuable: no new dependency, testable today.

cmd.Env = append(os.Environ(), …) handed every build step the runner service's entire environment. A step now gets a constructed one: PATH, HOME, LANG, CI, the GITBAY_* variables, and its secrets — which the server sends only for a trusted build, so a fork's merge request still gets none.

HOME is the workspace rather than the runner's home. That is a change the design does not call for and I think it should: tools read credentials out of dotfiles — .netrc, .npmrc, .gitconfig — and a build has no business finding the runner's. It also puts a build's caches in the workspace, where they go away with it.

PATH is the one value carried over, with a fallback: without it a step cannot find the tools the host was provisioned with.

This does not close the key-theft path — a step can still read the runner's SSH key off the disk by path. That is what the container split in the second merge request is for; this one narrows what a step is handed.

TestStepEnv* set variables on the runner and assert they do not reach a step, check the constructed values, the secret passthrough, and the PATH fallback. The existing CI e2e suite passes against the constructed environment.

Stacked on !288.

Ref #144

retargeted from bookmarks-146 to main: !288 merged

2026-09-06 20:03 UTC