Accept the SSH private key base64-encoded #2

Merged
megamiley merged 1 commits from fix/base64-private-key into main 2026-09-28 13:50:10 +02:00
Collaborator

Problem

The runner masks secrets per log line, so a multi-line PEM key passed as private_key isn't matched and shows up in plain text in the step's env: block in the log. This leaked the dev deploy key in the Upload image + compose file to /opt/analytics step of the analytics-server deploy-dev workflow.

Change

  • private_key can now be a single-line base64-encoded key (base64 -w0 <keyfile>), which the runner masks like any other secret. It's decoded into the temp key file before use.
  • Values containing -----BEGIN are still written as-is, so existing callers passing a raw PEM key keep working (but remain unmasked).
  • Updated the input description.

Tested locally with a throwaway ed25519 key: both the raw and base64 forms produce a byte-identical, valid key file.

Rollout

Merge this (and the matching change in ssh-command) before switching DEV_SSH_PRIVATE_KEY to the base64 value, since the current main would write the base64 string out verbatim.

🤖 Generated with Claude Code

## Problem The runner masks secrets per log line, so a multi-line PEM key passed as `private_key` isn't matched and shows up in plain text in the step's `env:` block in the log. This leaked the dev deploy key in the `Upload image + compose file to /opt/analytics` step of the analytics-server `deploy-dev` workflow. ## Change - `private_key` can now be a single-line base64-encoded key (`base64 -w0 <keyfile>`), which the runner masks like any other secret. It's decoded into the temp key file before use. - Values containing `-----BEGIN` are still written as-is, so existing callers passing a raw PEM key keep working (but remain unmasked). - Updated the input description. Tested locally with a throwaway ed25519 key: both the raw and base64 forms produce a byte-identical, valid key file. ## Rollout Merge this (and the matching change in `ssh-command`) before switching `DEV_SSH_PRIVATE_KEY` to the base64 value, since the current `main` would write the base64 string out verbatim. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Claude added 1 commit 2026-09-28 13:49:15 +02:00
Multi-line secrets aren't masked by the runner, so a raw PEM key passed
as private_key ends up in plain text in the step's env block in the log.
Accept a single-line base64-encoded key instead, which is masked like
any other secret. Raw PEM keys still work for backwards compatibility.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
megamiley merged commit 63a8aa6f5a into main 2026-09-28 13:50:10 +02:00
megamiley deleted branch fix/base64-private-key 2026-09-28 13:50:10 +02:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: megamiley/ssh-upload#2