Secret environment variables may leak in GitPod workspace logs when embedded in larger strings
0 reputation · 21 Mar 2024, 06:05 UTC
Goal
Ensure that GitPod’s secret environment variables remain completely hidden in workspace logs, even when their values are concatenated with other text or appear inside error messages during integration‑testing scripts.
GitPod masks variables marked as secret in the terminal output, but the masking logic may only replace exact matches. If a secret value is printed as part of a larger string (e.g., echo \"Token=$GITPOD_TEST_TOKEN\") or is embedded in an exception stack trace, the original value could still be visible. Additionally, it is unclear whether a changed secret variable is immediately reflected in new workspaces or if a cached value from a previous prebuild can be reused.
- Does GitPod’s secret masking replace only exact matches or also substrings within log output?
- If a secret variable is concatenated with other text before being printed, will the masked value still appear?
- Does changing a secret variable’s value trigger an immediate update in subsequent workspace starts, or can a cached value be reused across prebuilds?