Compare commits

...
Author SHA1 Message Date
megamileyandClaude Opus 5.5 4b9b56ff8d Accept the SSH private key base64-encoded
Multi-line secrets aren't masked by the runner, so a raw PEM key passed
as ssh-key can end up in plain text in the step's env block in the log.
Accept a single-line base64-encoded key instead, which is masked like
any other secret. Raw PEM keys still work for backwards compatibility.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 14:15:44 +02:00
megamiley abfcc1f965 Merge pull request 'Accept ssh-key as raw PEM, drop base64 requirement' (#1) from fix/raw-key-no-base64 into main
Reviewed-on: #1
2026-08-06 08:52:19 +00:00
Claude 4fea231b5f Accept ssh-key as a raw PEM key, drop base64 requirement
ssh-key was expected to be base64-encoded and decoded with
`base64 --decode`, which is inconsistent with ssh-upload and
ssh-command (both take the raw PEM directly) and an easy way to end
up with a silently corrupt key file if the stored secret isn't
actually base64. Write the input straight to the key file instead.
2026-08-06 08:51:01 +00:00
+14 -9
View File
@@ -3,7 +3,7 @@ description: 'Clones a repository via SSH on a custom port.'
inputs:
ssh-key:
description: 'Private SSH Key'
description: 'Private SSH Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.'
required: true
ref:
description: 'Branch, tag, or commit SHA to checkout'
@@ -37,11 +37,16 @@ runs:
# 1. Setup the SSH directory
mkdir -p ~/.ssh
chmod 700 ~/.ssh
# 2. Decode the Base64 secret back into a properly formatted file
echo "$SSH_KEY" | base64 --decode > ~/.ssh/gitea_key
# 2. Write the private key to a file
# The key is expected base64-encoded so it's a single-line secret the runner can mask;
# raw multi-line PEM keys are still accepted for backwards compatibility.
case "$SSH_KEY" in
*"-----BEGIN"*) printf '%s\n' "$SSH_KEY" > ~/.ssh/gitea_key ;;
*) printf '%s' "$SSH_KEY" | tr -d '[:space:]' | base64 -d > ~/.ssh/gitea_key ;;
esac
chmod 600 ~/.ssh/gitea_key
# 3. Configure SSH for the custom port and bypass host key prompt
cat >> ~/.ssh/config <<EOF
Host $HOST
@@ -50,19 +55,19 @@ runs:
IdentityFile ~/.ssh/gitea_key
StrictHostKeyChecking no
EOF
# 4. Ensure workspace is empty before cloning
cd $GITHUB_WORKSPACE
find . -mindepth 1 -delete
# 5. Clone the repository
echo "Cloning $REPO..."
git clone ssh://git@$HOST:$PORT/$REPO.git .
# 6. Checkout the specific ref
if [ -n "$REF" ]; then
echo "Checking out ref: $REF"
git checkout "$REF"
else
echo "No Ref provided to checkout!"
fi
fi