Skip to content

feat: forward allowlisted runtime environment to test container - #15

Merged
omermorad merged 4 commits into
mainfrom
codex/runtime-env-forwarding
Sep 29, 2026
Merged

omermorad merged 4 commits into
mainfrom
codex/runtime-env-forwarding

Conversation

@omermorad

Copy link
Copy Markdown
Contributor

Summary

Add optional runtime-env input to the root action and run subaction. Callers supply secret values via step env and list only newline-delimited variable names in the input. Only the Playwright execution container receives --env NAME; the build, merge, and report containers do not receive the allowlist.

Validation accepts portable identifiers, deduplicates names, rejects assignments and reserved runner/process-control variables, and requires every requested variable to be defined and non-empty. Invalid input fails closed as infrastructure-error with phase runtime-environment, before Docker starts. Errors do not echo raw input or values. Omitting the input preserves existing behavior.

README documents the interface, runtime-only credential handling, trusted-code/artifact boundaries, and pending release requirement. Future consumer: https://github.com/Nimbleway/unblocker/pull/3706.

Validation

  • 67 offline Node regression checks passed, including actual run-shell execution with mocked Docker, root-to-nested wiring, malformed and missing values, reserved variables, duplicate normalization, secret-safe output, and final failure classification.
  • Independent real Docker smoke passed using a synthetic multiline credential; unlisted variables remained absent inside the container.
  • Formatting, git diff --check, and all 3 local README links passed.
  • Documentation graph scripts are unavailable in this repository; both commands were attempted, with local link verification used instead.
  • No real credentials or staging requests were used.

Release dependency

Consumers must wait for a release containing this change under the selected major tag, such as codotech/playwright-e2e@v0. This PR does not publish a release, move tags, or change consumers to SHA/feature-branch references.

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

E2E test report

Gate ✅ passed
Caller SUT setup: success · cleanup: success · artifact: sut-logs
Tests 4 passed · 0 failed · 0 skipped · 4 total
Profile pull-request
Projects api, chromium
Tags @smoke (any)
Runner playwright-e2e-runner:e2e-71e07e6cd31ab60dec2f7df32fa2a6a5ad377dd62bb67b04fa80380c5ac696b1 (reused)
Results e2e-results
Report image playwright-e2e-report:36585494687-1 · e2e-report-image
Run Open workflow run

@omermorad
omermorad merged commit ffee1ed into main Sep 29, 2026
2 checks passed
@omermorad
omermorad deleted the codex/runtime-env-forwarding branch September 29, 2026 14:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant