BigW Consortium Gitlab
Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
G
gitlab-ce
Project
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
Registry
Registry
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Commits
Issue Boards
Open sidebar
Forest Godfrey
gitlab-ce
Commits
e8e2e8ca
Commit
e8e2e8ca
authored
Sep 08, 2017
by
Rémy Coutable
Browse files
Options
Browse Files
Download
Plain Diff
Merge branch 'patch-18' into 'master'
clarify that only some Runner Executors have these security concerns See merge request !14068
parents
a34555be
a13402da
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
4 additions
and
2 deletions
+4
-2
README.md
doc/ci/runners/README.md
+4
-2
No files found.
doc/ci/runners/README.md
View file @
e8e2e8ca
...
@@ -228,7 +228,8 @@ To make a Runner pick tagged/untagged jobs:
...
@@ -228,7 +228,8 @@ To make a Runner pick tagged/untagged jobs:
### Be careful with sensitive information
### Be careful with sensitive information
If you can run a job on a Runner, you can get access to any code it runs
With some
[
Runner Executors
](
https://docs.gitlab.com/runner/executors/README.html
)
,
if you can run a job on the Runner, you can get access to any code it runs
and get the token of the Runner. With shared Runners, this means that anyone
and get the token of the Runner. With shared Runners, this means that anyone
that runs jobs on the Runner, can access anyone else's code that runs on the
that runs jobs on the Runner, can access anyone else's code that runs on the
Runner.
Runner.
...
@@ -237,7 +238,8 @@ In addition, because you can get access to the Runner token, it is possible
...
@@ -237,7 +238,8 @@ In addition, because you can get access to the Runner token, it is possible
to create a clone of a Runner and submit false jobs, for example.
to create a clone of a Runner and submit false jobs, for example.
The above is easily avoided by restricting the usage of shared Runners
The above is easily avoided by restricting the usage of shared Runners
on large public GitLab instances and controlling access to your GitLab instance.
on large public GitLab instances, controlling access to your GitLab instance,
and using more secure
[
Runner Executors
](
https://docs.gitlab.com/runner/executors/README.html
)
.
### Forks
### Forks
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment