Accept the SSH private key base64-encoded

Multi-line secrets aren't masked by the runner, so a raw PEM key passed
as ssh-key can end up in plain text in the step's env block in the log.
Accept a single-line base64-encoded key instead, which is masked like
any other secret. Raw PEM keys still work for backwards compatibility.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
megamileyandClaude Opus 5.5 committed 2026-09-28 14:15:44 +02:00
1 parent abfcc1f965
commit 4b9b56ff8d
1 file changed
+8 -3
+8 -3
View File
@@ -3,7 +3,7 @@ description: 'Clones a repository via SSH on a custom port.'
inputs: inputs:
ssh-key: ssh-key:
description: 'Private SSH Key' description: 'Private SSH Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.'
required: true required: true
ref: ref:
description: 'Branch, tag, or commit SHA to checkout' description: 'Branch, tag, or commit SHA to checkout'
@@ -38,8 +38,13 @@ runs:
mkdir -p ~/.ssh mkdir -p ~/.ssh
chmod 700 ~/.ssh chmod 700 ~/.ssh
# 2. Write the private key to a file as-is # 2. Write the private key to a file
printf '%s\n' "$SSH_KEY" > ~/.ssh/gitea_key # The key is expected base64-encoded so it's a single-line secret the runner can mask;
# raw multi-line PEM keys are still accepted for backwards compatibility.
case "$SSH_KEY" in
*"-----BEGIN"*) printf '%s\n' "$SSH_KEY" > ~/.ssh/gitea_key ;;
*) printf '%s' "$SSH_KEY" | tr -d '[:space:]' | base64 -d > ~/.ssh/gitea_key ;;
esac
chmod 600 ~/.ssh/gitea_key chmod 600 ~/.ssh/gitea_key
# 3. Configure SSH for the custom port and bypass host key prompt # 3. Configure SSH for the custom port and bypass host key prompt