Accept the SSH private key base64-encoded
Multi-line secrets aren't masked by the runner, so a raw PEM key passed as private_key ends up in plain text in the step's env block in the log. Accept a single-line base64-encoded key instead, which is masked like any other secret. Raw PEM keys still work for backwards compatibility. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
1466448394
commit
95bd004534
1 file changed
+7
-2
+7
-2
@@ -3,7 +3,7 @@ description: 'Executes a shell command/script on a remote server via SSH on a cu
|
|||||||
|
|
||||||
inputs:
|
inputs:
|
||||||
private_key:
|
private_key:
|
||||||
description: 'Private SSH Key'
|
description: 'Private SSH Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.'
|
||||||
required: true
|
required: true
|
||||||
command:
|
command:
|
||||||
description: 'Shell command or multi-line script to run on the remote server'
|
description: 'Shell command or multi-line script to run on the remote server'
|
||||||
@@ -36,7 +36,12 @@ runs:
|
|||||||
# 1. Setup the SSH directory and private key
|
# 1. Setup the SSH directory and private key
|
||||||
mkdir -p ~/.ssh
|
mkdir -p ~/.ssh
|
||||||
chmod 700 ~/.ssh
|
chmod 700 ~/.ssh
|
||||||
echo "$SSH_KEY" > ~/.ssh/ssh_command_key
|
# The key is expected base64-encoded so it's a single-line secret the runner can mask;
|
||||||
|
# raw multi-line PEM keys are still accepted for backwards compatibility.
|
||||||
|
case "$SSH_KEY" in
|
||||||
|
*"-----BEGIN"*) echo "$SSH_KEY" > ~/.ssh/ssh_command_key ;;
|
||||||
|
*) printf '%s' "$SSH_KEY" | tr -d '[:space:]' | base64 -d > ~/.ssh/ssh_command_key ;;
|
||||||
|
esac
|
||||||
chmod 600 ~/.ssh/ssh_command_key
|
chmod 600 ~/.ssh/ssh_command_key
|
||||||
|
|
||||||
# 2. Configure SSH for the custom port/user and bypass host key prompt
|
# 2. Configure SSH for the custom port/user and bypass host key prompt
|
||||||
|
|||||||
Reference in new issue
Block a user