Pass AUR SSH key via GIT_SSH_COMMAND instead of ~/.ssh
This commit is contained in:
1 parent
7baaa60cf2
commit
bd4ed84ab3
1 file changed
+8
-10
@@ -113,18 +113,16 @@ if [[ -z "${AUR_SSH_PRIVATE_KEY:-}" ]]; then
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
mkdir -p ~/.ssh && chmod 700 ~/.ssh
|
# Pass the key and known_hosts explicitly instead of via ~/.ssh: in the CI
|
||||||
printf '%s\n' "$AUR_SSH_PRIVATE_KEY" > ~/.ssh/aur_key
|
# container $HOME and the passwd home directory disagree, and ssh resolves
|
||||||
chmod 600 ~/.ssh/aur_key
|
# "~" through the latter, silently ignoring anything written to $HOME/.ssh.
|
||||||
cat >> ~/.ssh/config <<'EOF'
|
sshdir="$(mktemp -d)"
|
||||||
Host aur.archlinux.org
|
printf '%s\n' "$AUR_SSH_PRIVATE_KEY" > "$sshdir/key"
|
||||||
User aur
|
chmod 600 "$sshdir/key"
|
||||||
IdentityFile ~/.ssh/aur_key
|
|
||||||
IdentitiesOnly yes
|
|
||||||
EOF
|
|
||||||
# Pinned host key, see https://aur.archlinux.org
|
# Pinned host key, see https://aur.archlinux.org
|
||||||
echo 'aur.archlinux.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuBKrPzbawxA/k2g6NcyV5jmqwJ2s+zpgZGZ7tpLIcN' \
|
echo 'aur.archlinux.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuBKrPzbawxA/k2g6NcyV5jmqwJ2s+zpgZGZ7tpLIcN' \
|
||||||
>> ~/.ssh/known_hosts
|
> "$sshdir/known_hosts"
|
||||||
|
export GIT_SSH_COMMAND="ssh -i $sshdir/key -o UserKnownHostsFile=$sshdir/known_hosts -o IdentitiesOnly=yes"
|
||||||
|
|
||||||
aurdir="$(mktemp -d)"
|
aurdir="$(mktemp -d)"
|
||||||
git clone "ssh://aur@aur.archlinux.org/$pkg.git" "$aurdir"
|
git clone "ssh://aur@aur.archlinux.org/$pkg.git" "$aurdir"
|
||||||
|
|||||||
Reference in new issue
Block a user