A reconnaissance tool for GitLab runner hosts that discovers and harvests CI/CD job artifacts, source code, registry images, secure files, and secrets.
gl-runner-harvester is designed for red-teamers and security researchers who have shell access to a GitLab runner host. It:
- Detects the GitLab runner executor type (shell, SSH, Docker, Kubernetes)
- Monitors active CI/CD job execution in real-time
- Harvests source code, environment variables, CI context, secure files, and registry images
- Scans harvested data for exposed secrets (PATs, runner tokens, API keys)
Run the harvester on a runner host to collect all active job artifacts:
./gl-runner-harvester harvest --collection-path /tmp/gl-harvest --interval 2 --log-level infoTo prevent disk exhaustion during long harvest runs, tune the write cutoff threshold (default is 95):
./gl-runner-harvester harvest --max-disk-usage-percent 90This will:
- Detect the runner executor type
- Poll for active CI/CD jobs every 2 seconds
- Collect job data into
/tmp/gl-harvest/<job_id>_<timestamp>/ - Scan harvested data for secrets
- Log progress and findings at info level
Example output directory structure:
/tmp/gl-harvest/
└── 14136599304_20260429_072045/
├── source/
├── secure_files/
├── image/
└── summary.json
Install the latest Linux/macOS release with:
curl -fsSL https://frjcomp.github.io/gl-runner-harvester/install.sh | shYou can also download binaries manually from GitHub Releases.