Do not commit plaintext secrets to this repository or to a separate private Git repository. Git history is not a secret manager.
Long-lived credentials, such as a GitHub App private key, belong only in the fleet controller or an external secret manager.
The controller should use that credential to generate short-lived just-in-time runner configuration. Job runner containers must not receive the long-lived key.
Project test or integration secrets belong in GitHub repository or environment secrets owned by the calling project. Reusable workflows should accept only explicitly declared secrets.
Normal validation should use no secret when possible. Deployment credentials must not be available to the normal shared validation pool.
A single-host prototype may use root-owned files outside the repository checkout, for example:
/etc/ci-fleet/secrets/github-app.pem
/etc/ci-fleet/host.env
/etc/ci-fleet/ci-fleet.env
host.env contains the App client ID, installation ID, private-key path, and runner TTL. ci-fleet.env is rendered from reviewed desired state plus those approved host fields. Neither contains the PEM or application secrets, but both remain root-owned mode 0600 because they describe the controller identity and private installation.
Credential files should be owned by root, readable only by their intended service, and mounted only into the controller. The installer never accepts a private key, token, or Git credential in a command-line argument.
For a distributed fleet, use a secret manager or encrypted configuration system with independently revocable host identities.
The controller service receives its host-local private key as a mounted file:
services:
controller:
secrets:
- github_app_private_key
secrets:
github_app_private_key:
file: /etc/ci-fleet/secrets/github-app.pemThe runner service must not receive this secret.
Committed examples may document:
- variable names;
- expected file locations;
- obviously nonfunctional organization names;
- safe default capacity;
- permission requirements.
Committed examples must not include:
- real tokens or keys;
- real environment files;
- internal addresses;
- production endpoints;
- private host inventories;
- encoded secrets.
Base64 is encoding, not encryption.