{"version":"2.1.283","anchor":"runner-moves-git-ssl-cainfo-git-ssl-no-verify-into-session","canonical_anchor":"runner-git-helpers-take-scoped-configenv-push-on-release-r","heading":"Self-hosted runners handle git certificates, TLS settings and credentials per source for governed git","tier":"notice","area":"Self-Hosted Runners","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/runner-moves-git-ssl-cainfo-git-ssl-no-verify-into-session","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Self-hosted runners handle git certificates, TLS settings and credentials per source for governed git\n\nSelf-hosted runners using governed git now build a certificate bundle, move GIT_SSL_* into session git config and pass per-source git environments\n\n**Unclear.** The exact rules for when the variables are moved or left in place are inferred from the warning messages rather than read directly.\n\n**What**\n\nA self-hosted runner is a machine you operate that runs Claude Code sessions. Governed git routes its git traffic through a git mount provided by Anthropic. Several things change in how these runners set up git:\n\n- **Certificate file.** When the operator has set `GIT_SSL_CAINFO` (a file of trusted certificate authorities, or CAs), the runner builds its own certificate file. It holds the machine's public CAs, read from `\/etc\/ssl\/certs\/ca-certificates.crt` or `\/etc\/pki\/tls\/certs\/ca-bundle.crt`, plus the operator's CAs. The runner uses it for its own fetches from the mount.\n\n- **Build failures.** If the file can't be built, the runner prints a warning naming the reason: the file is unreadable, over 1 MiB, not PEM, holds TRUSTED CERTIFICATE blocks, no system roots were found, a write failed, or `--capacity` is above 1. The runner never builds the file when capacity is above 1.\n\n- **Pushes on release.** Before pushing outcome branches that include governed sources, the runner rebuilds this file. If that fails, it logs that the runner's own git keeps `GIT_SSL_CAINFO`.\n\n- **Per-source git settings.** Each source on the mount carries its own `gitEnvironment`. It is passed to checkout hooks, the reset and fetch helpers, and outcome-branch create, fetch, delete and push, as extra per-command git config entries and environment overrides.\n\n- **Session environment.** Runner sessions add `gitEnvironment.envOverrides` on top of the base environment.\n\n- **TLS variables inside sessions.** For governed sessions on git 2.31 or newer, the runner removes `GIT_SSL_CAINFO` and `GIT_SSL_NO_VERIFY` from the environment. It writes `http.sslCAInfo` and `http.sslVerify=false` into the session's git config instead, so the mount and governed hosts are still verified. On older git, or when the value is unusable, the variables stay in place. Each outcome prints a `[runner:warn]` explanation.\n\n- **New warnings.** They cover `NO_PROXY` entries that cover governed hosts, and client-certificate variables (`GIT_SSL_CERT`, `GIT_SSL_KEY`) that would be offered to the session relay.\n\n- **Windows.** The runner reads the server-delivered session variables without regard to upper or lower case.\n\n- **Credential helpers.** Git config entries exported into `GIT_CONFIG_PARAMETERS` may now have an empty value when the key matches `credential.<scheme>:\/\/\u2026.helper`. An empty value clears the inherited list of credential helpers (programs git asks for passwords). All other entries still refuse empty values or characters the shell would act on.\n\n**Why**\n\nOperators behind a proxy that inspects TLS traffic often set `GIT_SSL_CAINFO` to only their company's CA. The mount presents a public certificate, so fetches from it could fail. The runner now combines both sets of CAs and applies git credentials and settings per source. Operators should read the new warnings. Because the TLS settings now live in the session's git config, any per-host `http.<url>.sslCAInfo` or `http.<url>.sslVerify` the operator has set can take effect for that host.\n\n- Area: Self-Hosted Runners\n- Names: `GIT_SSL_CAINFO`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}