Variables you set
Which of a flag, a variable and the config file wins is in Credential resolution. The runner is the exception: it uses only its own config file’s values.
Variables a build receives
outerlayer runner sets these for the hooks and the command. Its own
config file supplies them. Any OUTERLAYER_* in the shell that started the
runner is dropped.
Hooks and a build run on the host inherit the rest of the runner’s
environment, minus destination secrets. A container build gets none of the
host’s environment except the names in runner.build.variables. It also gets
the recipe’s containerEnv, each destination’s env, and the runner’s own
values in the last row below.
What each holds is in The build’s variables and the hook sections after it.
OUTERLAYER_OUTCOME is one of ok, incomplete, failed, timed_out,
idle, lease_lost, interrupted or stopped. It is empty when the
provision hook exited 75. ok means the command exited zero; any other exit
is failed.
The cleanup hook sees ok for every command that exited zero, because it
runs before the item’s checks are read. The release, and the report hook
after it, carry incomplete instead when the item has no pull request, or
those checks still fail or have no result. See When the command exits
0.
Even ok is not a full verdict on the work: the checks prove only what they
check.
OUTERLAYER_LOG is unset in the report hook’s start phase. The log will be
$OUTERLAYER_JOB_DIR/command.log.
Anything else a hook needs comes from outerlayer work status --item $OUTERLAYER_WORK --json and outerlayer work threads --item $OUTERLAYER_WORK --json. Neither carries the issue’s body.
In CI
Set the three credential variables as secrets and the CLI needs nologin:
outerlayer emit artifact anchors to the pull request from the CI environment without --pr. outerlayer work build records the CI run as the source.