ci: take the AUR key base64-encoded so the runner masks it [skip ci]
This commit is contained in:
1 parent
a019c66760
commit
806cbacd7e
2 files changed
+13
-2
No files matched your search
@@ -87,7 +87,9 @@ source in the `PKGBUILD` (and drop the `-bin` suffix), or don't package it.
|
|||||||
public key to it (AUR account settings).
|
public key to it (AUR account settings).
|
||||||
2. Add the matching **private** key as a repository secret named
|
2. Add the matching **private** key as a repository secret named
|
||||||
`AUR_SSH_PRIVATE_KEY`
|
`AUR_SSH_PRIVATE_KEY`
|
||||||
(Settings → Actions → Secrets → Add secret).
|
(Settings → Actions → Secrets → Add secret), **base64-encoded on one line**
|
||||||
|
(`base64 -w0 < key`). The Gitea runner prints each step's environment and
|
||||||
|
does not mask a multi-line secret, so a plain key would end up in the log.
|
||||||
3. Optionally set the repository variable `AUR_GIT_NAME` and the repository
|
3. Optionally set the repository variable `AUR_GIT_NAME` and the repository
|
||||||
**secret** `AUR_GIT_EMAIL` to control the commit identity used on the AUR
|
**secret** `AUR_GIT_EMAIL` to control the commit identity used on the AUR
|
||||||
(defaults: `Felitendo` / the maintainer's old GitHub noreply address).
|
(defaults: `Felitendo` / the maintainer's old GitHub noreply address).
|
||||||
|
|||||||
@@ -183,7 +183,16 @@ fi
|
|||||||
# container $HOME and the passwd home directory disagree, and ssh resolves
|
# container $HOME and the passwd home directory disagree, and ssh resolves
|
||||||
# "~" through the latter, silently ignoring anything written to $HOME/.ssh.
|
# "~" through the latter, silently ignoring anything written to $HOME/.ssh.
|
||||||
sshdir="$(mktemp -d)"
|
sshdir="$(mktemp -d)"
|
||||||
printf '%s\n' "$AUR_SSH_PRIVATE_KEY" > "$sshdir/key"
|
# The secret holds the key base64-encoded on one line. The Gitea runner prints
|
||||||
|
# each step's environment and only masks a secret it finds there word for
|
||||||
|
# word, but it prints a multi-line value with escaped newlines: a plain key
|
||||||
|
# would show up in the log in full.
|
||||||
|
if [[ "$AUR_SSH_PRIVATE_KEY" == -----BEGIN* ]]; then
|
||||||
|
echo "::error::$pkg: AUR_SSH_PRIVATE_KEY must be base64-encoded on one line" \
|
||||||
|
"(base64 -w0), or the runner prints it in the log."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
base64 -d <<< "$AUR_SSH_PRIVATE_KEY" > "$sshdir/key"
|
||||||
chmod 600 "$sshdir/key"
|
chmod 600 "$sshdir/key"
|
||||||
# Pinned host key, see https://aur.archlinux.org
|
# Pinned host key, see https://aur.archlinux.org
|
||||||
echo 'aur.archlinux.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuBKrPzbawxA/k2g6NcyV5jmqwJ2s+zpgZGZ7tpLIcN' \
|
echo 'aur.archlinux.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuBKrPzbawxA/k2g6NcyV5jmqwJ2s+zpgZGZ7tpLIcN' \
|
||||||
|
|||||||
Reference in new issue
Block a user