Skip to main content

Variables you set

Which of a flag, a variable and the config file wins is in Credential resolution. The runner is the exception: it uses only its own config file’s values.

Variables a build receives

outerlayer runner sets these for the hooks and the command. Its own config file supplies them. Any OUTERLAYER_* in the shell that started the runner is dropped. Hooks and a build run on the host inherit the rest of the runner’s environment, minus destination secrets. A container build gets none of the host’s environment except the names in runner.build.variables. It also gets the recipe’s containerEnv, each destination’s env, and the runner’s own values in the last row below. What each holds is in The build’s variables and the hook sections after it. OUTERLAYER_OUTCOME is one of ok, incomplete, failed, timed_out, idle, lease_lost, interrupted or stopped. It is empty when the provision hook exited 75. ok means the command exited zero; any other exit is failed. The cleanup hook sees ok for every command that exited zero, because it runs before the item’s checks are read. The release, and the report hook after it, carry incomplete instead when the item has no pull request, or those checks still fail or have no result. See When the command exits 0. Even ok is not a full verdict on the work: the checks prove only what they check. OUTERLAYER_LOG is unset in the report hook’s start phase. The log will be $OUTERLAYER_JOB_DIR/command.log. Anything else a hook needs comes from outerlayer work status --item $OUTERLAYER_WORK --json and outerlayer work threads --item $OUTERLAYER_WORK --json. Neither carries the issue’s body.

In CI

Set the three credential variables as secrets and the CLI needs no login:
outerlayer emit artifact anchors to the pull request from the CI environment without --pr. outerlayer work build records the CI run as the source.