Skip to content

ci(prober): robust deploy-key handling (fix 'error in libcrypto') - #77

Merged
ralyodio merged 1 commit into
masterfrom
fix-deploy-ssh-key
Jul 5, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix-deploy-ssh-key

Conversation

@ralyodio

@ralyodio ralyodio commented Jul 5, 2026

Copy link
Copy Markdown
Contributor

Why

The deploy-prober run failed at Ship prober + lib to droplet:

Load key "/home/runner/.ssh/id_deploy": error in libcrypto
ubuntu@scan.crawlproof.com: Permission denied (publickey).

error in libcrypto = the private key written from DROPLET_SSH_KEY is malformed — almost always CRLF line endings or a key that lost its internal newlines when the secret was saved. The step wrote the secret verbatim, so it can't recover from that and fails later with a confusing "Permission denied".

What

Configure SSH now:

  • strips \r (fixes CRLF keys),
  • accepts either a raw BEGIN… key or a base64-encoded one,
  • validates the key with ssh-keygen -y and fails fast with an actionable message,
  • passes the secret via env: rather than inline interpolation.

⚠️ If it still fails after this

Then the stored secret itself is truncated/mangled (not just CRLF) and must be re-added — the reliable way preserves the file exactly:

gh secret set DROPLET_SSH_KEY --repo profullstack/crawlproof.com < /path/to/id_deploy

(and ensure that key's public half is in ubuntu@scan.crawlproof.com:~/.ssh/authorized_keys).

🤖 Generated with Claude Code

The Configure SSH step wrote the key verbatim, so a key with CRLF line
endings (or one accidentally stored base64) produced 'Load key: error in
libcrypto' → 'Permission denied (publickey)'. Now strip CR, accept raw or
base64 keys, and validate the key with ssh-keygen -y so a malformed
DROPLET_SSH_KEY fails fast with an actionable message. Also pass the secret
via env instead of inline interpolation.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Jul 5, 2026

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 9afa500 into master Jul 5, 2026
8 checks passed
@ralyodio
ralyodio deleted the fix-deploy-ssh-key branch July 5, 2026 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant