Security attestation request — application process vs Railway console environment
sandra030294
HOBBYOP

2 hours ago

We are performing a credential-isolation review of a private TEST service.

Railway project ID: bc23ebee-9481-44ef-a5a4-58de7f6c5ff8

Environment ID: 60120da6-4be2-45ae-9f4c-f9650a0d5b9a

Service ID: d212366b-e037-4b58-93d4-35ff2fc74c4f

Deployment ID: 36dbcfb2-4433-43f9-b9f9-90038a6b909f

The service Variables page contains only our intended service configuration. However, a Railway administrative console shell exposes additional credential variable names, including RAILWAY_API_TOKEN and GH_TOKEN. We did not inspect or record their values. The console shell runs as root while our application process runs as UID 10001.

For our security review, please confirm whether RAILWAY_API_TOKEN, GH_TOKEN, or other console-specific credentials are injected into the actual application process for this deployment, or whether they exist only in the administrative console environment. We need variable names or presence/absence only. Please do not provide any secret values. If possible, please identify the Railway documentation or platform behavior establishing the separation between console-injected credentials and the application runtime environment.

Awaiting Railway Response

0 Replies

Status changed to Awaiting Railway Response Railway • about 2 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...