2 hours ago
We are performing a credential-isolation review of a private TEST service.
Railway project ID: bc23ebee-9481-44ef-a5a4-58de7f6c5ff8
Environment ID: 60120da6-4be2-45ae-9f4c-f9650a0d5b9a
Service ID: d212366b-e037-4b58-93d4-35ff2fc74c4f
Deployment ID: 36dbcfb2-4433-43f9-b9f9-90038a6b909f
The service Variables page contains only our intended service configuration. However, a Railway administrative console shell exposes additional credential variable names, including RAILWAY_API_TOKEN and GH_TOKEN. We did not inspect or record their values. The console shell runs as root while our application process runs as UID 10001.
For our security review, please confirm whether RAILWAY_API_TOKEN, GH_TOKEN, or other console-specific credentials are injected into the actual application process for this deployment, or whether they exist only in the administrative console environment. We need variable names or presence/absence only. Please do not provide any secret values. If possible, please identify the Railway documentation or platform behavior establishing the separation between console-injected credentials and the application runtime environment.
0 Replies
Status changed to Awaiting Railway Response Railway • about 2 hours ago