README.md 26,1 КБ
Newer Older
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
1
# GitLab CI/CD Variables
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
2

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
3
When receiving a job from GitLab CI, the [Runner] prepares the build environment.
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
4
It starts by setting a list of **predefined variables** (environment variables)
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
5
and a list of **user-defined variables**.
Douwe Maan's avatar
Douwe Maan включено в состав коммита
6

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
7
## Priority of variables
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
8

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
9
10
11
The variables can be overwritten and they take precedence over each other in
this order:

Shinya Maeda's avatar
Shinya Maeda включено в состав коммита
12
1. [Trigger variables][triggers] or [scheduled pipeline variables](../../user/project/pipelines/schedules.md#making-use-of-scheduled-pipeline-variables) (take precedence over all)
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
13
14
1. Project-level [secret variables](#secret-variables) or [protected secret variables](#protected-secret-variables)
1. Group-level [secret variables](#secret-variables) or [protected secret variables](#protected-secret-variables)
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
15
1. YAML-defined [job-level variables](../yaml/README.md#variables)
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
16
1. YAML-defined [global variables](../yaml/README.md#variables)
Adam Niedzielski's avatar
Adam Niedzielski включено в состав коммита
17
1. [Deployment variables](#deployment-variables)
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
18
19
1. [Predefined variables](#predefined-variables-environment-variables) (are the
   lowest in the chain)
Douwe Maan's avatar
Douwe Maan включено в состав коммита
20

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
21
For example, if you define `API_TOKEN=secure` as a secret variable and
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
22
`API_TOKEN=yaml` in your `.gitlab-ci.yml`, the `API_TOKEN` will take the value
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
23
`secure` as the secret variables are higher in the chain.
Douwe Maan's avatar
Douwe Maan включено в состав коммита
24

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
25
## Predefined variables (Environment variables)
Douwe Maan's avatar
Douwe Maan включено в состав коммита
26

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
27
28
29
Some of the predefined environment variables are available only if a minimum
version of [GitLab Runner][runner] is used. Consult the table below to find the
version of Runner required.
Douwe Maan's avatar
Douwe Maan включено в состав коммита
30

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
31
32
33
34
35
36
37
38
39
40
>**Note:**
Starting with GitLab 9.0, we have deprecated some variables. Read the
[9.0 Renaming](#9-0-renaming) section to find out their replacements. **You are
strongly advised to use the new variables as we will remove the old ones in
future GitLab releases.**

| Variable                        | GitLab | Runner | Description |
|-------------------------------- |--------|--------|-------------|
| **CI**                          | all    | 0.4    | Mark that job is executed in CI environment |
| **CI_COMMIT_REF_NAME**          | 9.0    | all    | The branch or tag name for which project is built |
Shinya Maeda's avatar
Shinya Maeda включено в состав коммита
41
| **CI_COMMIT_REF_SLUG**          | 9.0    | all    | `$CI_COMMIT_REF_NAME` lowercased, shortened to 63 bytes, and with everything except `0-9` and `a-z` replaced with `-`. No leading / trailing `-`. Use in URLs, host names and domain names. |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
42
43
| **CI_COMMIT_SHA**               | 9.0    | all    | The commit revision for which project is built |
| **CI_COMMIT_TAG**               | 9.0    | 0.5    | The commit tag name. Present only when building tags. |
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
44
| **CI_CONFIG_PATH**              | 9.4    | 0.5    | The path to CI config file. Defaults to `.gitlab-ci.yml` |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
45
| **CI_DEBUG_TRACE**              | all    | 1.7    | Whether [debug tracing](#debug-tracing) is enabled |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
46
| **CI_DISPOSABLE_ENVIRONMENT**   | all    | 10.1   | Marks that the job is executed in a disposable environment (something that is created only for this job and disposed of/destroyed after the execution - all executors except `shell` and `ssh`). If the environment is disposable, it is set to true, otherwise it is not defined at all. |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
47
48
| **CI_ENVIRONMENT_NAME**         | 8.15   | all    | The name of the environment for this job |
| **CI_ENVIRONMENT_SLUG**         | 8.15   | all    | A simplified version of the environment name, suitable for inclusion in DNS, URLs, Kubernetes labels, etc. |
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
49
| **CI_ENVIRONMENT_URL**          | 9.3    | all    | The URL of the environment for this job |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
50
51
52
53
54
55
56
57
58
| **CI_JOB_ID**                   | 9.0    | all    | The unique id of the current job that GitLab CI uses internally |
| **CI_JOB_MANUAL**               | 8.12   | all    | The flag to indicate that job was manually started |
| **CI_JOB_NAME**                 | 9.0    | 0.5    | The name of the job as defined in `.gitlab-ci.yml` |
| **CI_JOB_STAGE**                | 9.0    | 0.5    | The name of the stage as defined in `.gitlab-ci.yml` |
| **CI_JOB_TOKEN**                | 9.0    | 1.2    | Token used for authenticating with the GitLab Container Registry |
| **CI_REPOSITORY_URL**           | 9.0    | all    | The URL to clone the Git repository |
| **CI_RUNNER_DESCRIPTION**       | 8.10   | 0.5    | The description of the runner as saved in GitLab |
| **CI_RUNNER_ID**                | 8.10   | 0.5    | The unique id of runner being used |
| **CI_RUNNER_TAGS**              | 8.10   | 0.5    | The defined runner tags |
Taylor Braun-Jones's avatar
Taylor Braun-Jones включено в состав коммита
59
60
61
| **CI_RUNNER_VERSION**           | all    | 10.6   | GitLab Runner version that is executing the current job |
| **CI_RUNNER_REVISION**          | all    | 10.6   | GitLab Runner revision that is executing the current job |
| **CI_RUNNER_EXECUTABLE_ARCH**   | all    | 10.6   | The OS/architecture of the GitLab Runner executable (note that this is not necessarily the same as the environment of the executor) |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
62
63
| **CI_PIPELINE_ID**              | 8.10   | 0.5    | The unique id of the current pipeline that GitLab CI uses internally |
| **CI_PIPELINE_TRIGGERED**       | all    | all    | The flag to indicate that job was [triggered] |
Fabio Busatto's avatar
Fabio Busatto включено в состав коммита
64
| **CI_PIPELINE_SOURCE**          | 10.0   | all    | Indicates how the pipeline was triggered. Possible options are: `push`, `web`, `trigger`, `schedule`, `api`, and `pipeline`. For pipelines created before GitLab 9.5, this will show as `unknown` |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
65
66
| **CI_PROJECT_DIR**              | all    | all    | The full path where the repository is cloned and where the job is run |
| **CI_PROJECT_ID**               | all    | all    | The unique id of the current project that GitLab CI uses internally |
vanadium23's avatar
vanadium23 включено в состав коммита
67
| **CI_PROJECT_NAME**             | 8.10   | 0.5    | The project name that is currently being built (actually it is project folder name) |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
68
69
| **CI_PROJECT_NAMESPACE**        | 8.10   | 0.5    | The project namespace (username or groupname) that is currently being built |
| **CI_PROJECT_PATH**             | 8.10   | 0.5    | The namespace with project name |
vanadium23's avatar
vanadium23 включено в состав коммита
70
| **CI_PROJECT_PATH_SLUG**        | 9.3    | all    | `$CI_PROJECT_PATH` lowercased and with everything except `0-9` and `a-z` replaced with `-`. Use in URLs and domain names. |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
71
| **CI_PROJECT_URL**              | 8.10   | 0.5    | The HTTP address to access project |
Matija Čupić's avatar
Matija Čupić включено в состав коммита
72
| **CI_PROJECT_VISIBILITY**       | 10.3   | all    | The project visibility (internal, private, public) |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
73
74
75
76
77
78
79
80
| **CI_REGISTRY**                 | 8.10   | 0.5    | If the Container Registry is enabled it returns the address of GitLab's Container Registry |
| **CI_REGISTRY_IMAGE**           | 8.10   | 0.5    | If the Container Registry is enabled for the project it returns the address of the registry tied to the specific project |
| **CI_REGISTRY_PASSWORD**        | 9.0    | all    | The password to use to push containers to the GitLab Container Registry |
| **CI_REGISTRY_USER**            | 9.0    | all    | The username to use to push containers to the GitLab Container Registry |
| **CI_SERVER**                   | all    | all    | Mark that job is executed in CI environment |
| **CI_SERVER_NAME**              | all    | all    | The name of CI server that is used to coordinate jobs |
| **CI_SERVER_REVISION**          | all    | all    | GitLab revision that is used to schedule jobs |
| **CI_SERVER_VERSION**           | all    | all    | GitLab version that is used to schedule jobs |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
81
| **CI_SHARED_ENVIRONMENT**       | all    | 10.1   | Marks that the job is executed in a shared environment (something that is persisted across CI invocations like `shell` or `ssh` executor). If the environment is shared, it is set to true, otherwise it is not defined at all. |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
82
83
84
85
86
| **ARTIFACT_DOWNLOAD_ATTEMPTS**  | 8.15   | 1.9    | Number of attempts to download artifacts running a job |
| **GET_SOURCES_ATTEMPTS**        | 8.15   | 1.9    | Number of attempts to fetch sources running a job |
| **GITLAB_CI**                   | all    | all    | Mark that job is executed in GitLab CI environment |
| **GITLAB_USER_ID**              | 8.12   | all    | The id of the user who started the job |
| **GITLAB_USER_EMAIL**           | 8.12   | all    | The email of the user who started the job |
Mark Fletcher's avatar
Mark Fletcher включено в состав коммита
87
| **GITLAB_USER_LOGIN**           | 10.0   | all    | The login username of the user who started the job |
Mark Fletcher's avatar
Mark Fletcher включено в состав коммита
88
| **GITLAB_USER_NAME**            | 10.0   | all    | The real name of the user who started the job |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
89
| **RESTORE_CACHE_ATTEMPTS**      | 8.15   | 1.9    | Number of attempts to restore the cache running a job |
Mayra Cabrera's avatar
Mayra Cabrera включено в состав коммита
90
91
| **CI_DEPLOY_USER**              | 10.8   | all    | Authentication username of the [GitLab Deploy Token][gitlab-deploy-token], only present if the Project has one related.|
| **CI_DEPLOY_PASSWORD**          | 10.8   | all    | Authentication password of the [GitLab Deploy Token][gitlab-deploy-token], only present if the Project has one related.|
Douwe Maan's avatar
Douwe Maan включено в состав коммита
92

Z.J. van de Weg's avatar
Z.J. van de Weg включено в состав коммита
93
94
## 9.0 Renaming

Ville Skyttä's avatar
Ville Skyttä включено в состав коммита
95
To follow conventions of naming across GitLab, and to further move away from the
Z.J. van de Weg's avatar
Z.J. van de Weg включено в состав коммита
96
97
98
`build` term and toward `job` CI variables have been renamed for the 9.0
release.

Fabio Busatto's avatar
Fabio Busatto включено в состав коммита
99
100
101
102
103
>**Note:**
Starting with GitLab 9.0, we have deprecated the `$CI_BUILD_*` variables. **You are
strongly advised to use the new variables as we will remove the old ones in
future GitLab releases.**

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
104
105
106
107
108
109
110
111
112
| 8.x name              | 9.0+ name               |
| --------------------- |------------------------ |
| `CI_BUILD_ID`         | `CI_JOB_ID`             |
| `CI_BUILD_REF`        | `CI_COMMIT_SHA`         |
| `CI_BUILD_TAG`        | `CI_COMMIT_TAG`         |
| `CI_BUILD_REF_NAME`   | `CI_COMMIT_REF_NAME`    |
| `CI_BUILD_REF_SLUG`   | `CI_COMMIT_REF_SLUG`    |
| `CI_BUILD_NAME`       | `CI_JOB_NAME`           |
| `CI_BUILD_STAGE`      | `CI_JOB_STAGE`          |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
113
| `CI_BUILD_REPO`       | `CI_REPOSITORY_URL`     |
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
114
115
116
| `CI_BUILD_TRIGGERED`  | `CI_PIPELINE_TRIGGERED` |
| `CI_BUILD_MANUAL`     | `CI_JOB_MANUAL`         |
| `CI_BUILD_TOKEN`      | `CI_JOB_TOKEN`          |
Z.J. van de Weg's avatar
Z.J. van de Weg включено в состав коммита
117

Mathijs de Kruyf's avatar
Mathijs de Kruyf включено в состав коммита
118
## `.gitlab-ci.yml` defined variables
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
119
120
121

>**Note:**
This feature requires GitLab Runner 0.5.0 or higher and GitLab CI 7.14 or higher.
Douwe Maan's avatar
Douwe Maan включено в состав коммита
122

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
123
124
125
126
127
128
129
GitLab CI allows you to add to `.gitlab-ci.yml` variables that are set in the
build environment. The variables are hence saved in the repository, and they
are meant to store non-sensitive project configuration, e.g., `RAILS_ENV` or
`DATABASE_URL`.

For example, if you set the variable below globally (not inside a job), it will
be used in all executed commands and scripts:
Douwe Maan's avatar
Douwe Maan включено в состав коммита
130
131
132
133
134
135

```yaml
variables:
  DATABASE_URL: "postgres://postgres@postgres/my_database"
```

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
136
137
138
139
140
The YAML-defined variables are also set to all created
[service containers](../docker/using_docker_images.md), thus allowing to fine
tune them.

Variables can be defined at a global level, but also at a job level. To turn off
Tor Bechmann Yamamoto-Sørensen's avatar
Tor Bechmann Yamamoto-Sørensen включено в состав коммита
141
global defined variables in your job, define an empty hash:
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
142
143
144

```yaml
job_name:
Sébastien's avatar
Sébastien включено в состав коммита
145
  variables: {}
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
146
147
```

TeNNoX's avatar
TeNNoX включено в состав коммита
148
149
150
151
152
153
154
155
156
157
You are able to use other variables inside your variable definition (or escape them with `$$`):

```yaml
variables:
  LS_CMD: 'ls $FLAGS $$TMP_DIR'
  FLAGS: '-al'
script:
  - 'eval $LS_CMD'  # will execute 'ls -al $TMP_DIR'
```

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
158
## Secret variables
Douwe Maan's avatar
Douwe Maan включено в состав коммита
159

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
160
161
162
163
164
165
166
167
168
NOTE: **Note:**
Group-level secret variables were added in GitLab 9.4.

CAUTION: **Important:**
Be aware that secret variables are not masked, and their values can be shown
in the job logs if explicitly asked to do so. If your project is public or
internal, you can set the pipelines private from your [project's Pipelines
settings](../../user/project/pipelines/settings.md#visibility-of-pipelines).
Follow the discussion in issue [#13784][ce-13784] for masking the secret variables.
Douwe Maan's avatar
Douwe Maan включено в состав коммита
169

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
170
171
172
173
174
GitLab CI allows you to define per-project or per-group secret variables
that are set in the pipeline environment. The secret variables are stored out of
the repository (not in `.gitlab-ci.yml`) and are securely passed to GitLab Runner
making them available during a pipeline run. It's the recommended method to
use for storing things like passwords, SSH keys and credentials.
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
175

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
176
Project-level secret variables can be added by going to your project's
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
177
**Settings > CI/CD**, then finding the section called **Secret variables**.
Douwe Maan's avatar
Douwe Maan включено в состав коммита
178

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
179
Likewise, group-level secret variables can be added by going to your group's
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
180
**Settings > CI/CD**, then finding the section called **Secret variables**.
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
181
Any variables of [subgroups] will be inherited recursively.
Douwe Maan's avatar
Douwe Maan включено в состав коммита
182

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
183
184
![Secret variables](img/secret_variables.png)

Shinya Maeda's avatar
Shinya Maeda включено в состав коммита
185
186
Once you set them, they will be available for all subsequent pipelines. You can also
[protect your variables](#protected-secret-variables).
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
187

Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
188
### Protected secret variables
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
189
190

>**Notes:**
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
191
This feature requires GitLab 9.3 or higher.
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
192

Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
193
Secret variables could be protected. Whenever a secret variable is
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
194
protected, it would only be securely passed to pipelines running on the
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
195
[protected branches] or [protected tags]. The other pipelines would not get any
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
196
197
198
protected variables.

Protected variables can be added by going to your project's
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
199
200
**Settings > CI/CD**, then finding the section called
**Secret variables**, and check "Protected".
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
201
202

Once you set them, they will be available for all subsequent pipelines.
Nick Thomas's avatar
Nick Thomas включено в состав коммита
203

Adam Niedzielski's avatar
Adam Niedzielski включено в состав коммита
204
205
206
207
208
## Deployment variables

>**Note:**
This feature requires GitLab CI 8.15 or higher.

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
209
[Project services](../../user/project/integrations/project_services.md) that are
Adam Niedzielski's avatar
Adam Niedzielski включено в состав коммита
210
211
responsible for deployment configuration may define their own variables that
are set in the build environment. These variables are only defined for
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
212
[deployment jobs](../environments.md). Please consult the documentation of
Adam Niedzielski's avatar
Adam Niedzielski включено в состав коммита
213
214
215
the project services that you are using to learn which variables they define.

An example project service that defines deployment variables is
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
216
[Kubernetes Service](../../user/project/integrations/kubernetes.md#deployment-variables).
Adam Niedzielski's avatar
Adam Niedzielski включено в состав коммита
217

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
218
219
220
## Debug tracing

> Introduced in GitLab Runner 1.7.
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
221
222
223
224
225
226

CAUTION: **Warning:**
Enabling debug tracing can have severe security implications. The
output **will** contain the content of all your secret variables and any other
secrets! The output **will** be uploaded to the GitLab server and made visible
in job traces!
Nick Thomas's avatar
Nick Thomas включено в состав коммита
227
228

By default, GitLab Runner hides most of the details of what it is doing when
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
229
processing a job. This behavior keeps job traces short, and prevents secrets
Nick Thomas's avatar
Nick Thomas включено в состав коммита
230
231
232
233
234
from being leaked into the trace unless your script writes them to the screen.

If a job isn't working as expected, this can make the problem difficult to
investigate; in these cases, you can enable debug tracing in `.gitlab-ci.yml`.
Available on GitLab Runner v1.7+, this feature enables the shell's execution
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
235
trace, resulting in a verbose job trace listing all commands that were run,
Nick Thomas's avatar
Nick Thomas включено в состав коммита
236
237
variables that were set, etc.

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
238
Before enabling this, you should ensure jobs are visible to
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
239
[team members only](../../user/permissions.md#project-features). You should
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
240
also [erase](../pipelines.md#seeing-build-status) all generated job traces
Nick Thomas's avatar
Nick Thomas включено в состав коммита
241
242
243
244
245
before making them visible again.

To enable debug traces, set the `CI_DEBUG_TRACE` variable to `true`:

```yaml
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
246
job_name:
Nick Thomas's avatar
Nick Thomas включено в состав коммита
247
248
249
250
  variables:
    CI_DEBUG_TRACE: "true"
```

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
Example truncated output with debug trace set to true:

```bash
...

export CI_SERVER_TLS_CA_FILE="/builds/gitlab-examples/ci-debug-trace.tmp/CI_SERVER_TLS_CA_FILE"
if [[ -d "/builds/gitlab-examples/ci-debug-trace/.git" ]]; then
  echo $'\''\x1b[32;1mFetching changes...\x1b[0;m'\''
  $'\''cd'\'' "/builds/gitlab-examples/ci-debug-trace"
  $'\''git'\'' "config" "fetch.recurseSubmodules" "false"
  $'\''rm'\'' "-f" ".git/index.lock"
  $'\''git'\'' "clean" "-ffdx"
  $'\''git'\'' "reset" "--hard"
  $'\''git'\'' "remote" "set-url" "origin" "https://gitlab-ci-token:xxxxxxxxxxxxxxxxxxxx@example.com/gitlab-examples/ci-debug-trace.git"
  $'\''git'\'' "fetch" "origin" "--prune" "+refs/heads/*:refs/remotes/origin/*" "+refs/tags/*:refs/tags/*"
else
  $'\''mkdir'\'' "-p" "/builds/gitlab-examples/ci-debug-trace.tmp/git-template"
  $'\''rm'\'' "-r" "-f" "/builds/gitlab-examples/ci-debug-trace"
  $'\''git'\'' "config" "-f" "/builds/gitlab-examples/ci-debug-trace.tmp/git-template/config" "fetch.recurseSubmodules" "false"
  echo $'\''\x1b[32;1mCloning repository...\x1b[0;m'\''
  $'\''git'\'' "clone" "--no-checkout" "https://gitlab-ci-token:xxxxxxxxxxxxxxxxxxxx@example.com/gitlab-examples/ci-debug-trace.git" "/builds/gitlab-examples/ci-debug-trace" "--template" "/builds/gitlab-examples/ci-debug-trace.tmp/git-template"
  $'\''cd'\'' "/builds/gitlab-examples/ci-debug-trace"
fi
echo $'\''\x1b[32;1mChecking out dd648b2e as master...\x1b[0;m'\''
$'\''git'\'' "checkout" "-f" "-q" "dd648b2e48ce6518303b0bb580b2ee32fadaf045"
'
+++ hostname
++ echo 'Running on runner-8a2f473d-project-1796893-concurrent-0 via runner-8a2f473d-machine-1480971377-317a7d0f-digital-ocean-4gb...'
Running on runner-8a2f473d-project-1796893-concurrent-0 via runner-8a2f473d-machine-1480971377-317a7d0f-digital-ocean-4gb...
++ export CI=true
++ CI=true
++ export CI_DEBUG_TRACE=false
++ CI_DEBUG_TRACE=false
Zeger-Jan van de Weg's avatar
Zeger-Jan van de Weg включено в состав коммита
284
285
++ export CI_COMMIT_SHA=dd648b2e48ce6518303b0bb580b2ee32fadaf045
++ CI_COMMIT_SHA=dd648b2e48ce6518303b0bb580b2ee32fadaf045
Z.J. van de Weg's avatar
Z.J. van de Weg включено в состав коммита
286
287
288
289
290
291
292
293
294
295
++ export CI_COMMIT_BEFORE_SHA=dd648b2e48ce6518303b0bb580b2ee32fadaf045
++ CI_COMMIT_BEFORE_SHA=dd648b2e48ce6518303b0bb580b2ee32fadaf045
++ export CI_COMMIT_REF_NAME=master
++ CI_COMMIT_REF_NAME=master
++ export CI_JOB_ID=7046507
++ CI_JOB_ID=7046507
++ export CI_REPOSITORY_URL=https://gitlab-ci-token:xxxxxxxxxxxxxxxxxxxx@example.com/gitlab-examples/ci-debug-trace.git
++ CI_REPOSITORY_URL=https://gitlab-ci-token:xxxxxxxxxxxxxxxxxxxx@example.com/gitlab-examples/ci-debug-trace.git
++ export CI_JOB_TOKEN=xxxxxxxxxxxxxxxxxxxx
++ CI_JOB_TOKEN=xxxxxxxxxxxxxxxxxxxx
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
++ export CI_PROJECT_ID=1796893
++ CI_PROJECT_ID=1796893
++ export CI_PROJECT_DIR=/builds/gitlab-examples/ci-debug-trace
++ CI_PROJECT_DIR=/builds/gitlab-examples/ci-debug-trace
++ export CI_SERVER=yes
++ CI_SERVER=yes
++ export 'CI_SERVER_NAME=GitLab CI'
++ CI_SERVER_NAME='GitLab CI'
++ export CI_SERVER_VERSION=
++ CI_SERVER_VERSION=
++ export CI_SERVER_REVISION=
++ CI_SERVER_REVISION=
++ export GITLAB_CI=true
++ GITLAB_CI=true
++ export CI=true
++ CI=true
++ export GITLAB_CI=true
++ GITLAB_CI=true
Z.J. van de Weg's avatar
Z.J. van de Weg включено в состав коммита
314
315
316
317
318
319
320
321
322
323
324
325
326
327
++ export CI_JOB_ID=7046507
++ CI_JOB_ID=7046507
++ export CI_JOB_TOKEN=xxxxxxxxxxxxxxxxxxxx
++ CI_JOB_TOKEN=xxxxxxxxxxxxxxxxxxxx
++ export CI_COMMIT_REF=dd648b2e48ce6518303b0bb580b2ee32fadaf045
++ CI_COMMIT_REF=dd648b2e48ce6518303b0bb580b2ee32fadaf045
++ export CI_COMMIT_BEFORE_SHA=dd648b2e48ce6518303b0bb580b2ee32fadaf045
++ CI_COMMIT_BEFORE_SHA=dd648b2e48ce6518303b0bb580b2ee32fadaf045
++ export CI_COMMIT_REF_NAME=master
++ CI_COMMIT_REF_NAME=master
++ export CI_COMMIT_NAME=debug_trace
++ CI_JOB_NAME=debug_trace
++ export CI_JOB_STAGE=test
++ CI_JOB_STAGE=test
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
++ export CI_SERVER_NAME=GitLab
++ CI_SERVER_NAME=GitLab
++ export CI_SERVER_VERSION=8.14.3-ee
++ CI_SERVER_VERSION=8.14.3-ee
++ export CI_SERVER_REVISION=82823
++ CI_SERVER_REVISION=82823
++ export CI_PROJECT_ID=17893
++ CI_PROJECT_ID=17893
++ export CI_PROJECT_NAME=ci-debug-trace
++ CI_PROJECT_NAME=ci-debug-trace
++ export CI_PROJECT_PATH=gitlab-examples/ci-debug-trace
++ CI_PROJECT_PATH=gitlab-examples/ci-debug-trace
++ export CI_PROJECT_NAMESPACE=gitlab-examples
++ CI_PROJECT_NAMESPACE=gitlab-examples
++ export CI_PROJECT_URL=https://example.com/gitlab-examples/ci-debug-trace
++ CI_PROJECT_URL=https://example.com/gitlab-examples/ci-debug-trace
++ export CI_PIPELINE_ID=52666
++ CI_PIPELINE_ID=52666
++ export CI_RUNNER_ID=1337
++ CI_RUNNER_ID=1337
++ export CI_RUNNER_DESCRIPTION=shared-runners-manager-1.example.com
++ CI_RUNNER_DESCRIPTION=shared-runners-manager-1.example.com
Pawel Chojnacki's avatar
Pawel Chojnacki включено в состав коммита
350
351
++ export 'CI_RUNNER_TAGS=shared, docker, linux, ruby, mysql, postgres, mongo'
++ CI_RUNNER_TAGS='shared, docker, linux, ruby, mysql, postgres, mongo'
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
352
353
354
355
356
357
358
++ export CI_REGISTRY=registry.example.com
++ CI_REGISTRY=registry.example.com
++ export CI_DEBUG_TRACE=true
++ CI_DEBUG_TRACE=true
++ export GITLAB_USER_ID=42
++ GITLAB_USER_ID=42
++ export GITLAB_USER_EMAIL=user@example.com
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
359
++ GITLAB_USER_EMAIL=user@example.com
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
360
361
362
363
364
365
366
367
++ export VERY_SECURE_VARIABLE=imaverysecurevariable
++ VERY_SECURE_VARIABLE=imaverysecurevariable
++ mkdir -p /builds/gitlab-examples/ci-debug-trace.tmp
++ echo -n '-----BEGIN CERTIFICATE-----
MIIFQzCCBCugAwIBAgIRAL/ElDjuf15xwja1ZnCocWAwDQYJKoZIhvcNAQELBQAw'

...
```
Nick Thomas's avatar
Nick Thomas включено в состав коммита
368

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
369
## Using the CI variables in your job scripts
Douwe Maan's avatar
Douwe Maan включено в состав коммита
370

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
371
372
All variables are set as environment variables in the build environment, and
they are accessible with normal methods that are used to access such variables.
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
373
In most cases `bash` or `sh` is used to execute the job script.
Douwe Maan's avatar
Douwe Maan включено в состав коммита
374

John Spaetzel's avatar
John Spaetzel включено в состав коммита
375
To access environment variables, use the syntax for your Runner's [shell][shellexecutors].
Kamil Trzcinski's avatar
Kamil Trzcinski включено в состав коммита
376

John Spaetzel's avatar
John Spaetzel включено в состав коммита
377
378
379
380
381
382
383
384
385
| Shell                | Usage           |
|----------------------|-----------------|
| bash/sh              | `$variable`     |
| windows batch        | `%variable%`    |
| PowerShell           | `$env:variable` |

To access environment variables in bash, prefix the variable name with (`$`):

```yaml
Douwe Maan's avatar
Douwe Maan включено в состав коммита
386
387
job_name:
  script:
Elan Ruusamäe's avatar
Elan Ruusamäe включено в состав коммита
388
    - echo $CI_JOB_ID
Douwe Maan's avatar
Douwe Maan включено в состав коммита
389
390
```

John Spaetzel's avatar
John Spaetzel включено в состав коммита
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
To access environment variables in **Windows Batch**, surround the variable
with (`%`):

```yaml
job_name:
  script:
    - echo %CI_JOB_ID%
```

To access environment variables in a **Windows PowerShell** environment, prefix
the variable name with (`$env:`):

```yaml
job_name:
  script:
    - echo $env:CI_JOB_ID
```

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
409
You can also list all environment variables with the `export` command,
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
410
but be aware that this will also expose the values of all the secret variables
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
411
you set, in the job log:
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
412

John Spaetzel's avatar
John Spaetzel включено в состав коммита
413
```yaml
Douwe Maan's avatar
Douwe Maan включено в состав коммита
414
415
416
417
job_name:
  script:
    - export
```
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
418

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
419
420
421
422
423
424
Example values:

```bash
export CI_JOB_ID="50"
export CI_COMMIT_SHA="1ecfd275763eff1d6b4844ea3168962458c9f27a"
export CI_COMMIT_REF_NAME="master"
Mustafa YILDIRIM's avatar
Mustafa YILDIRIM включено в состав коммита
425
export CI_REPOSITORY_URL="https://gitlab-ci-token:abcde-1234ABCD5678ef@example.com/gitlab-org/gitlab-ce.git"
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
export CI_COMMIT_TAG="1.0.0"
export CI_JOB_NAME="spec:other"
export CI_JOB_STAGE="test"
export CI_JOB_MANUAL="true"
export CI_JOB_TRIGGERED="true"
export CI_JOB_TOKEN="abcde-1234ABCD5678ef"
export CI_PIPELINE_ID="1000"
export CI_PROJECT_ID="34"
export CI_PROJECT_DIR="/builds/gitlab-org/gitlab-ce"
export CI_PROJECT_NAME="gitlab-ce"
export CI_PROJECT_NAMESPACE="gitlab-org"
export CI_PROJECT_PATH="gitlab-org/gitlab-ce"
export CI_PROJECT_URL="https://example.com/gitlab-org/gitlab-ce"
export CI_REGISTRY="registry.example.com"
export CI_REGISTRY_IMAGE="registry.example.com/gitlab-org/gitlab-ce"
export CI_RUNNER_ID="10"
export CI_RUNNER_DESCRIPTION="my runner"
export CI_RUNNER_TAGS="docker, linux"
export CI_SERVER="yes"
export CI_SERVER_NAME="GitLab"
export CI_SERVER_REVISION="70606bf"
export CI_SERVER_VERSION="8.9.0"
export GITLAB_USER_ID="42"
export GITLAB_USER_EMAIL="user@example.com"
export CI_REGISTRY_USER="gitlab-ci-token"
export CI_REGISTRY_PASSWORD="longalfanumstring"
```

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
454
455
456
457
458
## Variables expressions

> Variables expressions were added in GitLab 10.7.

It is possible to use variables expressions with only / except policies in
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
459
460
`.gitlab-ci.yml`. By using this approach you can limit what jobs are going to
be created within a pipeline after pushing a code to GitLab.
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
461
462
463
464
465
466
467
468
469
470
471
472
473
474

This is particularly useful in combination with secret variables and triggered
pipeline variables.

```yaml
deploy:
  script: cap staging deploy
  environment: staging
  only:
    variables:
      - $RELEASE == "staging"
      - $STAGING
```

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
475
Each expression provided is going to be evaluated before creating a pipeline.
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
476
477

If any of the conditions in `variables` evaluates to truth when using `only`,
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
478
479
a new job is going to be created. If any of the expressions evaluates to truth
when `except` is being used, a job is not going to be created.
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
480

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
481
This follows usual rules for [`only` / `except` policies][builds-policies].
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
482
483
484

### Supported syntax

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
485
Below you can find supported syntax reference:
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
486

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
487
1. Equality matching using a string
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
488

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
489
    > Example: `$VARIABLE == "some value"`
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
490
491
492
493
494
495

    You can use equality operator `==` to compare a variable content to a
    string. We support both, double quotes and single quotes to define a string
    value, so both `$VARIABLE == "some value"` and `$VARIABLE == 'some value'`
    are supported. `"some value" == $VARIABLE` is correct too.

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
496
1. Checking for an undefined value
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
497

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
498
499
500
501
    > Example: `$VARIABLE == null`

    It sometimes happens that you want to check whether a variable is defined
    or not. To do that, you can compare a variable to `null` keyword, like
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
502
    `$VARIABLE == null`. This expression is going to evaluate to truth if
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
503
    variable is not defined.
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
504

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
505
506
1. Checking for an empty variable

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
507
508
    > Example: `$VARIABLE == ""`

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
509
510
511
512
    If you want to check whether a variable is defined, but is empty, you can
    simply compare it against an empty string, like `$VAR == ''`.

1. Comparing two variables
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
513

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
514
515
516
517
    > Example: `$VARIABLE_1 == $VARIABLE_2`

    It is possible to compare two variables. This is going to compare values
    of these variables.
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
518

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
519
1. Variable presence check
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
520

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
521
522
    > Example: `$STAGING`

Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
523
524
525
526
    If you only want to create a job when there is some variable present,
    which means that it is defined and non-empty, you can simply use
    variable name as an expression, like `$STAGING`. If `$STAGING` variable
    is defined, and is non empty, expression will evaluate to truth.
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
    `$STAGING` value needs to a string, with length higher than zero.
    Variable that contains only whitespace characters is not an empty variable.

### Unsupported predefined variables

Because GitLab evaluates variables before creating jobs, we do not support a
few variables that depend on persistence layer, like `$CI_JOB_ID`.

Environments (like `production` or `staging`) are also being created based on
what jobs pipeline consists of, thus some environment-specific variables are
not supported as well.

We do not support variables containing tokens because of security reasons.

You can find a full list of unsupported variables below:

- `CI_JOB_ID`
- `CI_JOB_TOKEN`
- `CI_BUILD_ID`
- `CI_BUILD_TOKEN`
- `CI_REGISTRY_USER`
- `CI_REGISTRY_PASSWORD`
- `CI_REPOSITORY_URL`
- `CI_ENVIRONMENT_URL`
Mayra Cabrera's avatar
Mayra Cabrera включено в состав коммита
551
552
- `CI_DEPLOY_USER`
- `CI_DEPLOY_PASSWORD`
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
553

Pascal Borreli's avatar
Pascal Borreli включено в состав коммита
554
These variables are also not supported in a context of a
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
555
556
[dynamic environment name][dynamic-environments].

Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
557
[ce-13784]: https://gitlab.com/gitlab-org/gitlab-ce/issues/13784 "Simple protection of CI secret variables"
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
558
[eep]: https://about.gitlab.com/products/ "Available only in GitLab Premium"
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
559
[envs]: ../environments.md
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
560
561
[protected branches]: ../../user/project/protected_branches.md
[protected tags]: ../../user/project/protected_tags.md
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
562
[runner]: https://docs.gitlab.com/runner/
John Spaetzel's avatar
John Spaetzel включено в состав коммита
563
[shellexecutors]: https://docs.gitlab.com/runner/executors/
Lin Jen-Shin's avatar
Lin Jen-Shin включено в состав коммита
564
565
[triggered]: ../triggers/README.md
[triggers]: ../triggers/README.md#pass-job-variables-to-a-trigger
Achilleas Pipinellis's avatar
Achilleas Pipinellis включено в состав коммита
566
[subgroups]: ../../user/group/subgroups/index.md
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
567
[builds-policies]: ../yaml/README.md#only-and-except-complex
Grzegorz Bizon's avatar
Grzegorz Bizon включено в состав коммита
568
[dynamic-environments]: ../environments.md#dynamic-environments
Mayra Cabrera's avatar
Mayra Cabrera включено в состав коммита
569
[gitlab-deploy-token]: ../../user/project/deploy_tokens/index.md#gitlab-deploy-token