Runners attached to repositories !354

merged merged by cmc on 2026-09-09 23:02 UTC · krz/gitbay:user-runners into main

Discussion

cmc

A runner key claims builds only for the repositories it is attached to (repo runner add|list|remove, also on the settings page). runner next skips untrusted builds unless --untrusted; runner log and runner done refuse a build outside the key's attachments; the bypass is a full-scope admin key, not the account. Migration 0050 adds runner_repos and rekeys runner_seen by key. gitbay-runner init, config.toml, -identity, -untrusted. Wiki: Users, Admin, Threat-Model, Parity, FAQ, CI.

After deploy, attach the bay1 runner to krz/gitbay and cmc/ci-smoke as the admin; until then it claims nothing. The bay1 unit gains -untrusted.

Ref #184