When a shell runners starts on a server with the command given at creation like:
./start.sh --accountUuid {XXXXXXXXXXXXXXXXXXXXX} --repositoryUuid {XXXXXXXXXXXXXXXXXXXXXXXX} --runnerUuid {XXXXXXXXXXXXXXXXXXXXXXXXXXX} --OAuthClientId XXXXXXXXXXXXXXXXXXXXXX --OAuthClientSecret XXXXXXXXXXXXXX-XXXXXXXXXXXXXXXXXXXXXXXXXXXXX --runtime linux-shell --workingDirectory ../temp
This exposes all the credentials to anyone using a communal server, where you can use ps or top to see this command get all the OAuthClientId, OAuthClientSecret, etc from the command running.
is there a way the runner can be started with this data in a file like /etc/runner.env or environment variables so it's not exposed via the process inspection tools?