Gemini CLI
Operating Gemini CLI on workers — sign-in, why --skip-trust matters, sessions, add-on models through a separate settings home, and troubleshooting.
Sign-in
Sign in to Gemini CLI once as the worker's user. Missing credentials end a run with exit code 41 ("Please set an Auth method"), which the worker reports as authentication required.
How it runs
gemini --yolo --skip-trust -o stream-json --session-id <uuid> -p <prompt>. --skip-trust prevents Gemini CLI
from silently downgrading --yolo to asking for approval in a folder it does not trust yet, which would stall a
headless run.
Sessions
The worker assigns each session an id. Resuming by id could not be verified — sessions are saved only after a successful exchange — so recovery starts a fresh session from the checkpoint.
Add-on models
Gateway sessions use GOOGLE_GEMINI_BASE_URL with API-key authentication in a settings home of their own
(GEMINI_CLI_HOME), because Gemini CLI 0.61 rejects its gateway auth type in headless runs. Settings from your
own Gemini home, such as its MCP servers, are not loaded in those sessions.