What
A self-hosted runner is a machine you operate that runs Claude Code sessions. Governed git routes its git traffic through a git mount provided by Anthropic. Several things change in how these runners set up git:
- Certificate file. When the operator has set
GIT_SSL_CAINFO(a file of trusted certificate authorities, or CAs), the runner builds its own certificate file. It holds the machine's public CAs, read from/etc/ssl/certs/ca-certificates.crtor/etc/pki/tls/certs/ca-bundle.crt, plus the operator's CAs. The runner uses it for its own fetches from the mount. - Build failures. If the file can't be built, the runner prints a warning naming the reason: the file is unreadable, over 1 MiB, not PEM, holds TRUSTED CERTIFICATE blocks, no system roots were found, a write failed, or
--capacityis above 1. The runner never builds the file when capacity is above 1. - Pushes on release. Before pushing outcome branches that include governed sources, the runner rebuilds this file. If that fails, it logs that the runner's own git keeps
GIT_SSL_CAINFO. - Per-source git settings. Each source on the mount carries its own
gitEnvironment. It is passed to checkout hooks, the reset and fetch helpers, and outcome-branch create, fetch, delete and push, as extra per-command git config entries and environment overrides. - Session environment. Runner sessions add
gitEnvironment.envOverrideson top of the base environment. - TLS variables inside sessions. For governed sessions on git 2.31 or newer, the runner removes
GIT_SSL_CAINFOandGIT_SSL_NO_VERIFYfrom the environment. It writeshttp.sslCAInfoandhttp.sslVerify=falseinto the session's git config instead, so the mount and governed hosts are still verified. On older git, or when the value is unusable, the variables stay in place. Each outcome prints a[runner:warn]explanation. - New warnings. They cover
NO_PROXYentries that cover governed hosts, and client-certificate variables (GIT_SSL_CERT,GIT_SSL_KEY) that would be offered to the session relay. - Windows. The runner reads the server-delivered session variables without regard to upper or lower case.
- Credential helpers. Git config entries exported into
GIT_CONFIG_PARAMETERSmay now have an empty value when the key matchescredential.<scheme>://….helper. An empty value clears the inherited list of credential helpers (programs git asks for passwords). All other entries still refuse empty values or characters the shell would act on.
Why
Operators behind a proxy that inspects TLS traffic often set GIT_SSL_CAINFO to only their company's CA. The mount presents a public certificate, so fetches from it could fail. The runner now combines both sets of CAs and applies git credentials and settings per source. Operators should read the new warnings. Because the TLS settings now live in the session's git config, any per-host http.<url>.sslCAInfo or http.<url>.sslVerify the operator has set can take effect for that host.
The exact rules for when the variables are moved or left in place are inferred from the warning messages rather than read directly.
Self-hosted runner: Changed GIT_SSL_CAINFO and GIT_SSL_NO_VERIFY under Anthropic-managed git: the runner's own git always verifies…