Skip to content

Guardrails / Collectors

CI environment ​

Where the build is running: which CI provider, whether the runner is hosted or self hosted, what triggered it, and whether federated credentials are available to it.

Facts keyenv
Versionv1
Scriptenv.py
Timeout30 seconds

Inputs ​

InputDescriptionDefaultEnvironment
envFileRead the environment from this KEY=VALUE file instead of the process environment. Meant for testing a guardrail against a runner you are not on.``GUARDRAIL_INPUT_ENVFILE

When a guardrail declares an input with the same name, it passes its value through. That means you set these values in the guardrail's configuration in buildnote.json.

A guardrail asks for these facts by name and reads them back by the same name:

json
{
  "collect": ["env"]
}
python
env = guardrail.facts("env")

Facts ​

These are the fields of the document env collects. In a path, [] means each entry of the list before it, and [path] means a key of the object before it.

FactMeaning
ciWhether the build is running on a CI runner at all, as opposed to a developer's workstation.
providerCI provider recognised from its own variables: github, gitlab, jenkins, azure, circle, buildkite, teamcity, bitbucket, drone, travis, or local when none is recognised.
hostedWhether the runner is the provider's own hosted fleet. false for a self hosted runner, null when the provider does not say.
triggerWhat started the build, as the provider names it, or null.
pullRequestWhether the build is for a pull or merge request.
forkWhether that request came from a fork, null when the provider does not say. A fork build is the one that must run without secrets.
runner.osOperating system the runner reports, or null.
runner.archArchitecture the runner reports, or null.
runner.nameName the runner reports, or null.
oidcWhether a federated identity token is available to this job, so a pipeline can reach a cloud without a long lived key.
variablesNames of the CI variables that were set. Names only, never values: the facts are attached to the run event and a value can be a credential.

If a collector can't finish, it prints what it gathered so far along with an incomplete key that says why. Facts after the point where it stopped are missing, so a check that depends on them should read incomplete first.

Example facts ​

Here are the facts the env collector gathers from an example project:

json
{
  "provider": "github",
  "ci": true,
  "hosted": true,
  "trigger": "pull_request",
  "pullRequest": true,
  "fork": null,
  "runner": {
    "os": "Linux",
    "arch": "X64",
    "name": "GitHub Actions 4"
  },
  "oidc": true,
  "variables": [
    "CI",
    "GITHUB_ACTIONS",
    "GITHUB_BASE_REF",
    "GITHUB_EVENT_NAME",
    "GITHUB_HEAD_REF",
    "GITHUB_RUN_ID",
    "GITHUB_WORKFLOW",
    "RUNNER_ARCH",
    "RUNNER_ENVIRONMENT",
    "RUNNER_NAME",
    "RUNNER_OS"
  ]
}

Collected for ​

GuardrailCategoryInputs
build/runs-on-hosted-cibuildnone

All collectors

Buildnote Limited
Registered in England and Wales, Reg: 16140412