Environments
Versioned bundles of variables, secret files, and repository links.
An Environment stores variables, secret files, and linked repositories for an
organization. Secret values are encrypted at rest and stay masked on reads;
they are revealed only through the explicit reveal call
(POST /v1/environments/:ref/secrets:reveal), which requires admin rights.
Every change creates a new version, and a Dock records the Environment name and version pin it was created with.
Who can launch docks with secrets
Anything an Environment passes into a Dock (variables, secret files, agent provider keys, and the Dock API key) is readable by anyone inside that Dock. Masking and the admin-only reveal call protect the stored values, not a running Dock, so anyone who can reach a Dock that received them can read them.
The secretsAccess setting controls who that is:
members: any organization member can create, branch, or resume a Dock from this Environment, and read its secrets inside that Dock.admins(default for new Environments): only organization admins and owners can. A member is refused with403 environment_secrets_admin_only, before anything is provisioned, only when the launch would pass something readable into the Dock: at least one secret variable or file (with secrets passing on), the Dock API key, or agent credentials (with agent credentials passing on) while the organization has provider keys for the default agent or, for a Dock another user created, that user has a connected ChatGPT sign-in (a member's own sign-in never counts). Nothing is silently stripped. An Environment that would pass none of these, such as the emptybaseEnvironment of a new organization, or one marked safe for third parties, does not restrict members.
The restriction also covers reaching a Dock that already holds the bundle. For
a Dock another member created, a member is refused on exec, terminal, SSH,
port exposure, and snapshot file, tree, and download reads, and on branching,
resuming, or creating from a template of that Dock, even with noEnv or a
different Environment, because the copied disk carries the source's bundle. A
member's own Docks are not restricted, since they could only create them if
allowed. Admins and owners are never restricted.
Environments created before this default changed keep their existing value.
Only organization admins can change secretsAccess
(PATCH /v1/environments/:ref). Things to know:
- Switching to
adminsdoes not revoke bundles already delivered into existing Docks. Treat those secrets as exposed to whoever had access and rotate them if that matters. - "Upgrade all" re-applies the Environment to every Dock on it, including Docks created by members.
- Switching an Environment back to
membersremoves the restriction for Docks that already hold the bundle. - If the Environment a Dock was launched from is deleted, or re-created under the same name after the Dock, other members are refused on that Dock, since its disk may still hold the old bundle.
- An admin who branches or resumes with
noEnvproduces a Dock members can read. Apply scrubsenv.shand the manifest files, but derived artefacts may remain on the disk. - Run Docks are unaffected only when run egress is confined. With
RUN_EGRESS_ALLOW=*they go through the guard as the installer. - GitHub clone tokens are short-lived and visible in the process list while a clone is running.