Files
ssh-upload/action.yml
T
megamileyandClaude Opus 5.5 001cba3953 Accept the SSH private key base64-encoded
Multi-line secrets aren't masked by the runner, so a raw PEM key passed
as private_key ends up in plain text in the step's env block in the log.
Accept a single-line base64-encoded key instead, which is masked like
any other secret. Raw PEM keys still work for backwards compatibility.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 13:48:58 +02:00

80 lines
2.9 KiB
YAML

name: 'SSH Upload'
description: 'Upload files via SCP, automatically creating destination directories.'
author: 'MegaMiley Studio'
inputs:
host:
description: 'SSH Host IP or Domain'
required: true
port:
description: 'SSH Port (default: 22)'
required: false
default: '22'
username:
description: 'SSH Username'
required: true
private_key:
description: 'SSH Private Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.'
required: true
transfers:
description: 'List of transfers formatted as "source_file(s) | remote_destination". One per line.'
required: true
runs:
using: 'composite'
steps:
- name: Execute SSH/SCP Transfers
shell: bash
env:
PRIVATE_KEY: ${{ inputs.private_key }}
TRANSFERS: ${{ inputs.transfers }}
HOST: ${{ inputs.host }}
PORT: ${{ inputs.port }}
USERNAME: ${{ inputs.username }}
run: |
# 1. Create a secure temporary file for the SSH key
SSH_KEY_PATH=$(mktemp)
# The key is expected base64-encoded so it's a single-line secret the runner can mask;
# raw multi-line PEM keys are still accepted for backwards compatibility.
case "$PRIVATE_KEY" in
*"-----BEGIN"*) printf '%s\n' "$PRIVATE_KEY" > "$SSH_KEY_PATH" ;;
*) printf '%s' "$PRIVATE_KEY" | tr -d '[:space:]' | base64 -d > "$SSH_KEY_PATH" ;;
esac
chmod 600 "$SSH_KEY_PATH"
# 2. Add Host to known_hosts to prevent verification prompts
mkdir -p ~/.ssh
ssh-keyscan -p "$PORT" -H "$HOST" >> ~/.ssh/known_hosts 2>/dev/null
# 3. Securely write transfers input to a file for parsing
printf '%s\n' "$TRANSFERS" > transfers.txt
# 4. Loop through each line and execute commands
while IFS= read -r line || [ -n "$line" ]; do
# Skip empty lines
[[ -z "$(echo "$line" | tr -d '[:space:]')" ]] && continue
# Parse using the pipe | delimiter
IFS='|' read -r src dest <<< "$line"
# Trim leading and trailing whitespace
src=$(echo "$src" | sed -e 's/^[[:space:]]*//' -e 's/[[:space:]]*$//')
dest=$(echo "$dest" | sed -e 's/^[[:space:]]*//' -e 's/[[:space:]]*$//')
if [ -n "$src" ] && [ -n "$dest" ]; then
echo "::group::Transfer to $dest"
echo "Creating remote directory: $dest"
ssh -i "$SSH_KEY_PATH" -p "$PORT" "$USERNAME@$HOST" "mkdir -p \"$dest\"" < /dev/null
echo "Copying $src to $dest..."
# Note: eval is used so wildcards or multiple space-separated files expand properly
eval "scp -r -i \"$SSH_KEY_PATH\" -P $PORT $src \"$USERNAME@$HOST:$dest/\"" < /dev/null
echo "::endgroup::"
fi
done < transfers.txt
# 5. Cleanup
rm -f "$SSH_KEY_PATH" transfers.txt