Deploy self-hosted environments to production changedself-hosted-environments-deploy
Nearest release: v2.1.291, published under an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 6 Oct 2026 03:21 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 6 Oct 2026 03:37 UTC.
Upstream edited
Recorded here
Lines+3added
Lines−3removed
From line
132
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits31to this page, all time
The whole hunk
from line 132, old and new numbered
/
from line 132
132132
133133Without an identity, `git commit` fails with `Please tell me who you are` and sessions can't make progress. You can use your own bot identity instead; the runner doesn't override these values.
134134
135Don't bake long-lived or broadly-scoped push credentials into a shared runner image: a credential in the image is available to every session the image runs, whoever started it. Instead, mint a short-lived, least-scoped token per session from your [wrapper script](/docs/en/self-hosted-environments-configuration#wrapper-scripts), using the session creator's identity decoded from the session JWT. Pair it with an ephemeral per-session container, which requires `--capacity 1`, so no credential outlives the session that minted it; see the [hardening section](#harden-your-deployment).
135Don't bake long-lived or broadly scoped push credentials into a shared runner image: a credential in the image is available to every session the image runs, whoever started it. Instead, mint a short-lived, least-scoped token per session from your [wrapper script](/docs/en/self-hosted-environments-configuration#wrapper-scripts), using the session creator's identity decoded from the session JWT. Pair it with an ephemeral per-session container, which requires `--capacity 1`, so no credential outlives the session that minted it; see the [hardening section](#harden-your-deployment).
136136
137137If you must configure push credentials at the image level, for example for a read-only deploy key, scope them as tightly as your git host allows:
138138
139139* An SSH deploy key limited to one repository with a `url.<base>.insteadOf` rewrite
140* A `credential.helper` that returns a minimally-scoped token
141* `GIT_SSH_COMMAND` pointing at a narrowly-scoped key
140* A `credential.helper` that returns a minimally scoped token
141* `GIT_SSH_COMMAND` pointing at a narrowly scoped key
142142
143143Whichever mechanism you configure must work without a prompt, because the runner's built-in clone and fetch disable the prompts that git, SSH, and Git Credential Manager would otherwise show:
144144
No line in this hunk matches that.