The Air-Gapped CI Pipeline: Inside twentyhq/ci-privileged
How the open-source CRM Twenty isolated its GitHub Actions to solve the "pwn-request" problem, creating a zero-trust DMZ for automated code review.

Privileged CI operations for twentyhq/twenty. Handles PR comments, cross-repo posting, and other write operations isolated from contributor-accessible workflows.
- Twenty uses a dedicated utility repository to isolate high-privilege CI operations from untrusted contributor pull requests.
- The architecture relies on unidirectional trust, using repository dispatches to trigger workflows that solely pull static artifacts rather than executing external code.
- Defensive bash scripting with extensive retry loops handles the eventual consistency of the GitHub Actions artifact API.
The Open-Source Trust Paradox
When an open-source project runs Continuous Integration on a public pull request, it invites untrusted code into its infrastructure. If a workflow has write permissions or access to cloud secrets, a malicious contributor can alter the execution path to exfiltrate them. This is the "pwn-request" problem.
Standard mitigations often involve manual approvals or stripping permissions entirely. However, modern automated workflows require elevated access to post preview URLs, run visual regression tests, and analyze breaking changes. The team behind the Twenty CRM needed a way to maintain automation velocity without compromising security.
The Demilitarized Zone
To solve this, Twenty built ci-privileged. It acts as a highly restricted execution environment that holds sensitive tokens but never executes code from the main repository. The architecture enforces a strict unidirectional trust flow.
The main repository is treated as hostile. It can only emit a repository_dispatch signal across the boundary. The privileged repository wakes up, reaches across the boundary, and downloads static artifacts.
Defensive Engineering and Eventual Consistency
Because the privileged repository cannot rely on synchronous execution, it must poll the main repository for artifacts. The scripts use robust retry logic to account for the eventual consistency of the GitHub API.
for attempt in $(seq 1 30); do
# ... curl API ...
if [ -n "$ARTIFACT_URL" ]; then break; fi
sleep 30
done
Once the artifact is secured, the script parses the data and uses an HTML marker to upsert comments on the original pull request. This keeps the timeline clean rather than spamming the thread with new comments on every commit.
The Visual Regression Vault
The most complex workflow in this repository handles visual regression testing. It downloads a Storybook tarball, assumes an AWS OIDC role to upload it to S3, and calls a private Cloudflare-protected API to trigger a visual difference check.
By moving this entire sequence to the privileged repository, sensitive AWS and Cloudflare credentials never touch the main environment. The untrusted code has no pathway to the secrets.
The Cost of Paranoia
This custom approach offers a unique blend of automation velocity and token isolation. It is a masterclass in defensive infrastructure engineering for open source.
| Approach | Automation Velocity | Token Isolation | Setup Complexity |
|---|---|---|---|
| Dispatch DMZ (ci-privileged) | High | Complete | High |
| GitHub Environments | Low (Requires Manual Clicks) | Partial | Low |
| Cloud OIDC | High | Vulnerable (GitHub PR write tokens exposed) | Medium |