Merge pull request 'Accept the SSH private key base64-encoded' (#2) from fix/base64-private-key into main
Reviewed-on: #2
This commit was merged in pull request #2.
This commit is contained in:
commit
63a8aa6f5a
1 file changed
+7
-2
+7
-2
@@ -14,7 +14,7 @@ inputs:
|
|||||||
description: 'SSH Username'
|
description: 'SSH Username'
|
||||||
required: true
|
required: true
|
||||||
private_key:
|
private_key:
|
||||||
description: 'SSH Private Key'
|
description: 'SSH Private Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.'
|
||||||
required: true
|
required: true
|
||||||
transfers:
|
transfers:
|
||||||
description: 'List of transfers formatted as "source_file(s) | remote_destination". One per line.'
|
description: 'List of transfers formatted as "source_file(s) | remote_destination". One per line.'
|
||||||
@@ -34,7 +34,12 @@ runs:
|
|||||||
run: |
|
run: |
|
||||||
# 1. Create a secure temporary file for the SSH key
|
# 1. Create a secure temporary file for the SSH key
|
||||||
SSH_KEY_PATH=$(mktemp)
|
SSH_KEY_PATH=$(mktemp)
|
||||||
printf '%s\n' "$PRIVATE_KEY" > "$SSH_KEY_PATH"
|
# The key is expected base64-encoded so it's a single-line secret the runner can mask;
|
||||||
|
# raw multi-line PEM keys are still accepted for backwards compatibility.
|
||||||
|
case "$PRIVATE_KEY" in
|
||||||
|
*"-----BEGIN"*) printf '%s\n' "$PRIVATE_KEY" > "$SSH_KEY_PATH" ;;
|
||||||
|
*) printf '%s' "$PRIVATE_KEY" | tr -d '[:space:]' | base64 -d > "$SSH_KEY_PATH" ;;
|
||||||
|
esac
|
||||||
chmod 600 "$SSH_KEY_PATH"
|
chmod 600 "$SSH_KEY_PATH"
|
||||||
|
|
||||||
# 2. Add Host to known_hosts to prevent verification prompts
|
# 2. Add Host to known_hosts to prevent verification prompts
|
||||||
|
|||||||
Reference in new issue
Block a user