Validate source SSH secret before loading credentials
Some checks failed
Canary release / release (push) Failing after 19m46s

This commit is contained in:
Alois 2026-10-04 23:05:23 +02:00
commit 1afc431e67
Signed by: alois
SSH key fingerprint: SHA256:GBzT2DXvAuGV9XIV5W3WrzVpjU54FThmxHXdbz95J24

View file

@ -36,7 +36,16 @@ runs:
umask 077 umask 077
home="$RUNNER_TEMP/tensamin-source" home="$RUNNER_TEMP/tensamin-source"
mkdir -p "$home/.ssh" mkdir -p "$home/.ssh"
printf '%s\n' "$SOURCE_KEY" > "$home/.ssh/key" if [[ -z $SOURCE_KEY ]]; then
echo 'TENSAMIN_SOURCE_SSH_KEY is empty or unavailable to this repository workflow.' >&2
exit 1
fi
# Secret forms can preserve CRLF line endings from pasted key files.
printf '%s\n' "${SOURCE_KEY//$'\r'/}" > "$home/.ssh/key"
if ! ssh-keygen -y -P '' -f "$home/.ssh/key" >/dev/null 2>&1; then
echo 'TENSAMIN_SOURCE_SSH_KEY is not a valid unencrypted SSH private key. Verify the original file with ssh-keygen -y -P "" -f FILE, then replace the repository Actions secret with that file.' >&2
exit 1
fi
printf '%s\n' "$KNOWN_HOSTS" > "$home/.ssh/known_hosts" printf '%s\n' "$KNOWN_HOSTS" > "$home/.ssh/known_hosts"
printf 'Host *\n IdentityFile "%s/.ssh/key"\n IdentitiesOnly yes\n StrictHostKeyChecking yes\n UserKnownHostsFile "%s/.ssh/known_hosts"\n BatchMode yes\n' "$home" "$home" > "$home/.ssh/config" printf 'Host *\n IdentityFile "%s/.ssh/key"\n IdentitiesOnly yes\n StrictHostKeyChecking yes\n UserKnownHostsFile "%s/.ssh/known_hosts"\n BatchMode yes\n' "$home" "$home" > "$home/.ssh/config"
# An agent also supports Nix versions using libgit2 instead of Git's SSH command. # An agent also supports Nix versions using libgit2 instead of Git's SSH command.