Files
ssh-command/action.yml
T
megamileyandClaude Opus 5.5 95bd004534 Accept the SSH private key base64-encoded
Multi-line secrets aren't masked by the runner, so a raw PEM key passed
as private_key ends up in plain text in the step's env block in the log.
Accept a single-line base64-encoded key instead, which is masked like
any other secret. Raw PEM keys still work for backwards compatibility.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 13:48:59 +02:00

62 lines
2.2 KiB
YAML

name: 'Gitea SSH Command'
description: 'Executes a shell command/script on a remote server via SSH on a custom port.'
inputs:
private_key:
description: 'Private SSH Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.'
required: true
command:
description: 'Shell command or multi-line script to run on the remote server'
required: true
host:
description: 'Remote server hostname or IP'
required: true
username:
description: 'SSH username'
required: true
port:
description: 'SSH port'
required: false
default: '22'
runs:
using: "composite"
steps:
- name: Run SSH Command
shell: bash # Required for composite actions
env:
SSH_KEY: ${{ inputs.private_key }}
COMMAND: ${{ inputs.command }}
HOST: ${{ inputs.host }}
USERNAME: ${{ inputs.username }}
PORT: ${{ inputs.port }}
run: |
set -euo pipefail
# 1. Setup the SSH directory and private key
mkdir -p ~/.ssh
chmod 700 ~/.ssh
# The key is expected base64-encoded so it's a single-line secret the runner can mask;
# raw multi-line PEM keys are still accepted for backwards compatibility.
case "$SSH_KEY" in
*"-----BEGIN"*) echo "$SSH_KEY" > ~/.ssh/ssh_command_key ;;
*) printf '%s' "$SSH_KEY" | tr -d '[:space:]' | base64 -d > ~/.ssh/ssh_command_key ;;
esac
chmod 600 ~/.ssh/ssh_command_key
# 2. Configure SSH for the custom port/user and bypass host key prompt
cat >> ~/.ssh/config <<EOF
Host $HOST
Port $PORT
User $USERNAME
IdentityFile ~/.ssh/ssh_command_key
StrictHostKeyChecking no
EOF
# 3. Run the command on the remote host, piped over stdin so multi-line
# scripts and embedded quotes don't need any local shell-escaping.
# Remote stdout/stderr stream straight into this step's log, and the
# remote command's exit code becomes this step's exit code.
echo "Running command on $HOST..."
printf '%s\n' "$COMMAND" | ssh "$HOST" bash -s