Hello,
I'm running a Bitbucket Shell Runner on Linux using systemd.
I already moved some parameters to an environment file, and that partially worked.
However, sensitive information such as OAuth client ID, OAuth client secret still appear in systemctl status output because they are passed as Java -D options.
Also, according to a chat-bot based search, there seems to be no official support for loading secrets automatically from an env file in start.sh
Is there an official or recommended way to securely pass secrets to the runner without exposing them in the process list?
Thanks