Accept the SSH private key base64-encoded #2

Merged
megamiley merged 1 commits from fix/base64-private-key into main 2026-09-28 14:16:20 +02:00
Collaborator

Problem

The runner masks secrets per log line, so a multi-line PEM key passed as ssh-key can show up in plain text in the step's env: block in the log (this happened with the deploy key in ssh-upload). ssh-upload and ssh-command now accept a base64-encoded key, but this action still wrote the secret out as-is. A base64 GIT_SSH_KEY therefore ends up as an unparseable key file:

Load key "/root/.ssh/gitea_key": error in libcrypto
git@git.mmquack.nl: Permission denied (publickey).

(analytics-server run 1632, job 4219)

Change

  • ssh-key can now be a single-line base64-encoded key (base64 -w0 <keyfile>), which is decoded into ~/.ssh/gitea_key.
  • Values containing -----BEGIN are still written as-is, so existing callers passing a raw PEM key keep working (but remain unmasked).
  • Updated the input description.

Same logic as megamiley/ssh-upload#2 and megamiley/ssh-command#1.

🤖 Generated with Claude Code

## Problem The runner masks secrets per log line, so a multi-line PEM key passed as `ssh-key` can show up in plain text in the step's `env:` block in the log (this happened with the deploy key in `ssh-upload`). `ssh-upload` and `ssh-command` now accept a base64-encoded key, but this action still wrote the secret out as-is. A base64 `GIT_SSH_KEY` therefore ends up as an unparseable key file: ``` Load key "/root/.ssh/gitea_key": error in libcrypto git@git.mmquack.nl: Permission denied (publickey). ``` (analytics-server run 1632, job 4219) ## Change - `ssh-key` can now be a single-line base64-encoded key (`base64 -w0 <keyfile>`), which is decoded into `~/.ssh/gitea_key`. - Values containing `-----BEGIN` are still written as-is, so existing callers passing a raw PEM key keep working (but remain unmasked). - Updated the input description. Same logic as megamiley/ssh-upload#2 and megamiley/ssh-command#1. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Claude added 1 commit 2026-09-28 14:15:54 +02:00
Multi-line secrets aren't masked by the runner, so a raw PEM key passed
as ssh-key can end up in plain text in the step's env block in the log.
Accept a single-line base64-encoded key instead, which is masked like
any other secret. Raw PEM keys still work for backwards compatibility.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
megamiley merged commit 6b20155d94 into main 2026-09-28 14:16:20 +02:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: megamiley/ssh-checkout#2