repo deploy-key add does not forward stdin; the SSH API accepts the same key #55

closed cmc opened this on 2026-08-30 17:49 UTC

Discussion

cmc 2026-08-30 17:49 UTC

gitbay repo deploy-key add rejects a key file the SSH API accepts. Same file, back to back:

$ ssh-keygen -lf runner.pub
256 SHA256:b5HGR3H5A8Fb3A6aE08Qt1TZq8AoFSY/7cmoHThYevM ci-runner@bay1 (ED25519)

$ gitbay repo deploy-key add krz/orgo --rw < runner.pub
not a valid public key in authorized_keys format: ssh: no key found

$ ssh git@gitbay.org repo deploy-key add krz/orgo --rw < runner.pub
deploy key SHA256:b5HGR3H5A8Fb3A6aE08Qt1TZq8AoFSY/7cmoHThYevM (rw) bound to krz/orgo

The key is well-formed — ssh-keygen -lf parses it — and the server accepts it when the CLI is out of the path, so the CLI is not forwarding stdin to the remote command. Piping rather than redirecting fails the same way.

gitbay issue create --file - works, so this is not stdin handling in general. The commands documented as reading stdin (repo deploy-key add, repo secret set, release asset add, keys add) are worth checking together.

closed by commit dfc4fecaa3 by cmc: Resolve builds a dead runner abandoned, and forward bare-redirect stdin

2026-08-30 18:11 UTC