name: 'Gitea SSH Checkout' description: 'Clones a repository via SSH on a custom port.' inputs: ssh-key: description: 'Private SSH Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.' required: true ref: description: 'Branch, tag, or commit SHA to checkout' required: false default: '' repository: description: 'Repository to clone (e.g., owner/repo)' required: false default: ${{ github.repository }} host: description: 'Git server hostname' required: false default: 'git.mmquack.nl' port: description: 'SSH port' required: false default: '2222' runs: using: "composite" steps: - name: Run SSH Clone shell: bash # Required for composite actions env: SSH_KEY: ${{ inputs.ssh-key }} REF: ${{ inputs.ref }} REPO: ${{ inputs.repository }} HOST: ${{ inputs.host }} PORT: ${{ inputs.port }} run: | # 1. Setup the SSH directory mkdir -p ~/.ssh chmod 700 ~/.ssh # 2. Write the private key to a file # The key is expected base64-encoded so it's a single-line secret the runner can mask; # raw multi-line PEM keys are still accepted for backwards compatibility. case "$SSH_KEY" in *"-----BEGIN"*) printf '%s\n' "$SSH_KEY" > ~/.ssh/gitea_key ;; *) printf '%s' "$SSH_KEY" | tr -d '[:space:]' | base64 -d > ~/.ssh/gitea_key ;; esac chmod 600 ~/.ssh/gitea_key # 3. Configure SSH for the custom port and bypass host key prompt cat >> ~/.ssh/config <