name: Pinned source access description: Bootstrap public pinned tools before preparing private Nix source access inputs: source-key: description: SSH key with read access to locked sources required: true known-hosts: description: Verified SSH host keys required: true runs: using: composite steps: - name: Bootstrap tools from the public nixpkgs lock shell: bash run: | set -euo pipefail # Nix interpolation must remain literal for the evaluator. # shellcheck disable=SC2016 tools=$(nix build --impure --no-link --print-out-paths --expr ' let lock = builtins.fromJSON (builtins.readFile ./flake.lock); source = builtins.fetchTree lock.nodes.${lock.nodes.root.inputs.nixpkgs}.locked; pkgs = import source { system = builtins.currentSystem; }; in pkgs.buildEnv { name = "release-bootstrap"; paths = with pkgs; [ git openssh python3 bash coreutils ]; }') printf '%s/bin\n' "$tools" >> "$GITHUB_PATH" - name: Prepare SSH and checkout fetch credentials shell: bash env: SOURCE_KEY: ${{ inputs.source-key }} KNOWN_HOSTS: ${{ inputs.known-hosts }} run: | set -euo pipefail umask 077 home="$RUNNER_TEMP/tensamin-source" mkdir -p "$home/.ssh" printf '%s\n' "$SOURCE_KEY" > "$home/.ssh/key" printf '%s\n' "$KNOWN_HOSTS" > "$home/.ssh/known_hosts" printf 'Host *\n IdentityFile "%s/.ssh/key"\n IdentitiesOnly yes\n StrictHostKeyChecking yes\n UserKnownHostsFile "%s/.ssh/known_hosts"\n BatchMode yes\n' "$home" "$home" > "$home/.ssh/config" # An agent also supports Nix versions using libgit2 instead of Git's SSH command. eval "$(ssh-agent -s)" ssh-add "$home/.ssh/key" # The askpass process reads the token when Git invokes it. # shellcheck disable=SC2016 printf '#!/bin/sh\ncase "$1" in *Username*) printf "%%s\\n" token;; *) printf "%%s\\n" "$RELEASE_TOKEN";; esac\n' > "$home/askpass" chmod 700 "$home/askpass" printf 'HOME=%s\nGIT_SSH_COMMAND=ssh -F "%s/.ssh/config"\nGIT_ASKPASS=%s/askpass\nGIT_TERMINAL_PROMPT=0\nSSH_AUTH_SOCK=%s\nSSH_AGENT_PID=%s\n' "$home" "$home" "$home" "$SSH_AUTH_SOCK" "$SSH_AGENT_PID" >> "$GITHUB_ENV"