Accept ssh-key as a raw PEM key, drop base64 requirement
ssh-key was expected to be base64-encoded and decoded with `base64 --decode`, which is inconsistent with ssh-upload and ssh-command (both take the raw PEM directly) and an easy way to end up with a silently corrupt key file if the stored secret isn't actually base64. Write the input straight to the key file instead.
This commit is contained in:
+2
-2
@@ -38,8 +38,8 @@ runs:
|
|||||||
mkdir -p ~/.ssh
|
mkdir -p ~/.ssh
|
||||||
chmod 700 ~/.ssh
|
chmod 700 ~/.ssh
|
||||||
|
|
||||||
# 2. Decode the Base64 secret back into a properly formatted file
|
# 2. Write the private key to a file as-is
|
||||||
echo "$SSH_KEY" | base64 --decode > ~/.ssh/gitea_key
|
printf '%s\n' "$SSH_KEY" > ~/.ssh/gitea_key
|
||||||
chmod 600 ~/.ssh/gitea_key
|
chmod 600 ~/.ssh/gitea_key
|
||||||
|
|
||||||
# 3. Configure SSH for the custom port and bypass host key prompt
|
# 3. Configure SSH for the custom port and bypass host key prompt
|
||||||
|
|||||||
Reference in New Issue
Block a user