prod-pins/.forgejo/source-access/action.yml
Alois 1afc431e67
Some checks failed
Canary release / release (push) Failing after 19m46s
Validate source SSH secret before loading credentials
2026-10-04 23:05:23 +02:00

58 lines
2.8 KiB
YAML

name: Pinned source access
description: Bootstrap public pinned tools before preparing private Nix source access
inputs:
source-key:
description: SSH key with read access to locked sources
required: true
known-hosts:
description: Verified SSH host keys
required: true
runs:
using: composite
steps:
- name: Bootstrap tools from the public nixpkgs lock
shell: bash
run: |
set -euo pipefail
# Nix interpolation must remain literal for the evaluator.
# shellcheck disable=SC2016
tools=$(nix build --impure --no-link --print-out-paths --expr '
let
lock = builtins.fromJSON (builtins.readFile ./flake.lock);
source = builtins.fetchTree lock.nodes.${lock.nodes.root.inputs.nixpkgs}.locked;
pkgs = import source { system = builtins.currentSystem; };
in pkgs.buildEnv {
name = "release-bootstrap";
paths = with pkgs; [ git openssh python3 bash coreutils ];
}')
printf '%s/bin\n' "$tools" >> "$GITHUB_PATH"
- name: Prepare SSH and checkout fetch credentials
shell: bash
env:
SOURCE_KEY: ${{ inputs.source-key }}
KNOWN_HOSTS: ${{ inputs.known-hosts }}
run: |
set -euo pipefail
umask 077
home="$RUNNER_TEMP/tensamin-source"
mkdir -p "$home/.ssh"
if [[ -z $SOURCE_KEY ]]; then
echo 'TENSAMIN_SOURCE_SSH_KEY is empty or unavailable to this repository workflow.' >&2
exit 1
fi
# Secret forms can preserve CRLF line endings from pasted key files.
printf '%s\n' "${SOURCE_KEY//$'\r'/}" > "$home/.ssh/key"
if ! ssh-keygen -y -P '' -f "$home/.ssh/key" >/dev/null 2>&1; then
echo 'TENSAMIN_SOURCE_SSH_KEY is not a valid unencrypted SSH private key. Verify the original file with ssh-keygen -y -P "" -f FILE, then replace the repository Actions secret with that file.' >&2
exit 1
fi
printf '%s\n' "$KNOWN_HOSTS" > "$home/.ssh/known_hosts"
printf 'Host *\n IdentityFile "%s/.ssh/key"\n IdentitiesOnly yes\n StrictHostKeyChecking yes\n UserKnownHostsFile "%s/.ssh/known_hosts"\n BatchMode yes\n' "$home" "$home" > "$home/.ssh/config"
# An agent also supports Nix versions using libgit2 instead of Git's SSH command.
eval "$(ssh-agent -s)"
ssh-add "$home/.ssh/key"
# The askpass process reads the token when Git invokes it.
# shellcheck disable=SC2016
printf '#!/bin/sh\ncase "$1" in *Username*) printf "%%s\\n" token;; *) printf "%%s\\n" "$RELEASE_TOKEN";; esac\n' > "$home/askpass"
chmod 700 "$home/askpass"
printf 'HOME=%s\nGIT_SSH_COMMAND=ssh -F "%s/.ssh/config"\nGIT_ASKPASS=%s/askpass\nGIT_TERMINAL_PROMPT=0\nSSH_AUTH_SOCK=%s\nSSH_AGENT_PID=%s\n' "$home" "$home" "$home" "$SSH_AUTH_SOCK" "$SSH_AGENT_PID" >> "$GITHUB_ENV"