Right now `bazel run` relies on `bundle exec {ruby}` which is not hermetic - it uses the system Ruby for the initial bootstrap.