fix: introduce per-job cert volume with %gcl% token - #1877
Merged
Conversation
Jobs using docker:dind as a service share TLS client certificates via a named volume. The previous approach relied on a static volume name (e.g. `certs`) configured in .gitlab-ci-local-env, which caused race conditions when concurrent jobs wrote to and cleaned up the same volume. A new `%gcl-cert%:` prefix in VOLUME entries is now resolved at runtime to a per-job unique volume name (`gcl-<job>-<id>-cert`), matching the naming pattern of the existing build/tmp volumes. The `%gcl-cert%` token was chosen because Docker hard-rejects it if it ever reaches the daemon unsubstituted (invalid volume name character), rather than silently bind-mounting an unintended host path. Changes: - get certVolumeName() getter returning a per-job unique name - Cert volume is created and registered for cleanup alongside build/tmp volumes when any %gcl-cert%: entry is present in argv.volume - %gcl-cert%: prefix is resolved to certVolumeName in both the job container and service container volume loops
firecow
reviewed
Jun 22, 2026
ticapix
force-pushed
the
fix/per-job-cert-volume
branch
from
June 22, 2026 20:49
e3fcf9a to
96b49ce
Compare
firecow
approved these changes
Jun 23, 2026
tmeijn
pushed a commit
to tmeijn/dotfiles
that referenced
this pull request
Aug 11, 2026
This MR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [npm:gitlab-ci-local](https://github.com/firecow/gitlab-ci-local) | `4.73.0` → `4.74.0` |  |  |  |  | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>firecow/gitlab-ci-local (npm:gitlab-ci-local)</summary> ### [`v4.74.0`](https://github.com/firecow/gitlab-ci-local/releases/tag/4.74.0) [Compare Source](firecow/gitlab-ci-local@4.73.0...4.74.0) #### What's Changed - fix: introduce per-job cert volume with %gcl% token by [@​ticapix](https://github.com/ticapix) in [#​1877](firecow/gitlab-ci-local#1877) - fix: pull registry probe image before the timed readiness check by [@​firecow](https://github.com/firecow) in [#​1904](firecow/gitlab-ci-local#1904) - fix(parser): anchor comment directives correctly and quote injected descriptions by [@​firecow](https://github.com/firecow) in [#​1896](firecow/gitlab-ci-local#1896) **Full Changelog**: <firecow/gitlab-ci-local@4.73.0...4.74.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODguMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4OC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJSZW5vdmF0ZSBCb3QiLCJhdXRvbWF0aW9uOmJvdC1hdXRob3JlZCIsImRlcGVuZGVuY3ktdHlwZTo6bWlub3IiXX0=-->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hello,
This addresses #918
Jobs using docker:dind as a service share TLS client certificates via a named volume. The previous approach relied on a static volume name (e.g.
certs) configured in.gitlab-ci-local-env, which caused race conditions when concurrent jobs wrote to and cleaned up the same volume, each dind service writing its own certificates.A new
%gcl-cert%:prefix in VOLUME entries is now resolved at runtime to a per-job unique volume name (gcl-<job>-<id>-cert), matching the naming pattern of the existing build/tmp volumes.The
%gcl-cert%token was chosen because Docker hard-rejects it if it ever reaches the daemon unsubstituted (invalid volume name character), rather than silently bind-mounting an unintended host path.Changes:
I'm not sure how to add a test.
I used this config to test the implementation
The
.gitlab-ci-local-envlooks likeSummary by cubic
Adds a per-job cert volume for Docker-in-Docker by introducing a
%gcl-cert%:volume token. This prevents cross-job TLS cert races and cleanup conflicts when jobs run in parallel.Bug Fixes
certVolumeName(gcl-<job>-<id>-cert) when anyargv.volumestarts with%gcl-cert%:, matching build/tmp naming.%gcl-cert%:to the per-job name for both job and service--volumeflags before invoking Docker, avoiding accidental host bind mounts.Migration
certs:/certs/clientwith%gcl-cert%:/certs/clientto enable per-job isolation.Written for commit 96b49ce. Summary will update on new commits.