Multi-line secrets aren't masked by the runner, so a raw PEM key passed
as ssh-key can end up in plain text in the step's env block in the log.
Accept a single-line base64-encoded key instead, which is masked like
any other secret. Raw PEM keys still work for backwards compatibility.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ssh-key was expected to be base64-encoded and decoded with
`base64 --decode`, which is inconsistent with ssh-upload and
ssh-command (both take the raw PEM directly) and an easy way to end
up with a silently corrupt key file if the stored secret isn't
actually base64. Write the input straight to the key file instead.