From 6bca906662738fb3f06c2fd2c7edcc9f55d04315 Mon Sep 17 00:00:00 2001 From: Anthony Ettinger Date: Sun, 5 Jul 2026 15:18:54 +0000 Subject: [PATCH] ci(prober): robust deploy-key handling (fix 'error in libcrypto') MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Configure SSH step wrote the key verbatim, so a key with CRLF line endings (or one accidentally stored base64) produced 'Load key: error in libcrypto' → 'Permission denied (publickey)'. Now strip CR, accept raw or base64 keys, and validate the key with ssh-keygen -y so a malformed DROPLET_SSH_KEY fails fast with an actionable message. Also pass the secret via env instead of inline interpolation. Co-Authored-By: Claude Opus 4.8 --- .github/workflows/deploy-prober.yml | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/.github/workflows/deploy-prober.yml b/.github/workflows/deploy-prober.yml index 0cdee59c..95979c98 100644 --- a/.github/workflows/deploy-prober.yml +++ b/.github/workflows/deploy-prober.yml @@ -42,10 +42,25 @@ jobs: - uses: actions/checkout@v4 - name: Configure SSH + env: + DROPLET_SSH_KEY: ${{ secrets.DROPLET_SSH_KEY }} run: | install -m 700 -d ~/.ssh - printf '%s\n' "${{ secrets.DROPLET_SSH_KEY }}" > ~/.ssh/id_deploy + # Write the deploy key robustly: tolerate CRLF (a common cause of + # "error in libcrypto"), and accept either a raw OpenSSH/PEM key or a + # base64-encoded one. + if printf '%s' "$DROPLET_SSH_KEY" | grep -q 'BEGIN'; then + printf '%s\n' "$DROPLET_SSH_KEY" | tr -d '\r' > ~/.ssh/id_deploy + else + printf '%s' "$DROPLET_SSH_KEY" | tr -d '\r' | base64 -d > ~/.ssh/id_deploy + fi chmod 600 ~/.ssh/id_deploy + # Fail fast with a clear message if the key is malformed, instead of a + # confusing "Permission denied (publickey)" later. + if ! ssh-keygen -y -f ~/.ssh/id_deploy >/dev/null 2>&1; then + echo "::error::DROPLET_SSH_KEY is not a valid private key. Re-add it preserving newlines, e.g. 'gh secret set DROPLET_SSH_KEY --repo profullstack/crawlproof.com < id_deploy' (or store it base64-encoded)." + exit 1 + fi ssh-keyscan -H "$DEPLOY_HOST" >> ~/.ssh/known_hosts 2>/dev/null - name: Ship prober + lib to droplet