Question
Protected CI/CD Variables Missing in Production Pipeline
Zo Moss
0 reputation · 21 Jul 2023, 00:54 UTC
59.8K views0
Goal
Verify that protected variables are correctly injected into a production pipeline that runs on a protected branch or tag, while they work locally on a developer branch.
Constraints & Uncertainty
- Protected variables are only exposed to jobs triggered on protected refs, but the production ref may not be marked as protected in the current project settings.
- Variable masking rules may cause a value that is valid locally to be silently discarded when the mask constraints are not met in the production environment.
- Runner scope differences (project vs. group, Docker vs. shell executor) can alter the environment even with identical .gitlab-ci.yml files.
Questions
- Is the production branch or tag actually configured as protected in the project’s CI/CD settings?
- Do any protected variables in the pipeline violate masking constraints that would prevent them from being passed to the job?
- Could the runner used for production be a different executor or scope that omits variables present in the local environment?