Accept the SSH private key base64-encoded

Multi-line secrets aren't masked by the runner, so a raw PEM key passed
as private_key ends up in plain text in the step's env block in the log.
Accept a single-line base64-encoded key instead, which is masked like
any other secret. Raw PEM keys still work for backwards compatibility.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
megamileyandClaude Opus 5.5 committed 2026-09-28 13:48:58 +02:00
1 parent 994b093ada
commit 001cba3953
1 file changed
+7 -2
+7 -2
View File
@@ -14,7 +14,7 @@ inputs:
description: 'SSH Username'
required: true
private_key:
description: 'SSH Private Key'
description: 'SSH Private Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.'
required: true
transfers:
description: 'List of transfers formatted as "source_file(s) | remote_destination". One per line.'
@@ -34,7 +34,12 @@ runs:
run: |
# 1. Create a secure temporary file for the SSH key
SSH_KEY_PATH=$(mktemp)
printf '%s\n' "$PRIVATE_KEY" > "$SSH_KEY_PATH"
# The key is expected base64-encoded so it's a single-line secret the runner can mask;
# raw multi-line PEM keys are still accepted for backwards compatibility.
case "$PRIVATE_KEY" in
*"-----BEGIN"*) printf '%s\n' "$PRIVATE_KEY" > "$SSH_KEY_PATH" ;;
*) printf '%s' "$PRIVATE_KEY" | tr -d '[:space:]' | base64 -d > "$SSH_KEY_PATH" ;;
esac
chmod 600 "$SSH_KEY_PATH"
# 2. Add Host to known_hosts to prevent verification prompts