wiki: ssh's home inside a build container !364

merged merged by cmc on 2026-09-10 03:28 UTC · krz/gitbay:wiki-ssh-home into main

1 file changed, +7 −1

Layout: unified · split

.gitbay/wiki/Users.org +7 −1
@@ -474,7 +474,13 @@ from a runner elsewhere; inside a container on the server's own runner
474the host is at a private address the runner fills in). A job that 474the host is at a private address the runner fills in). A job that
475talks back to the instance — a release asset, a comment, a push to a 475talks back to the instance — a release asset, a comment, a push to a
476pages branch — uses =$GITBAY_SSH= with a key it holds as a secret; 476pages branch — uses =$GITBAY_SSH= with a key it holds as a secret;
477the build's container has no key of its own. 477the build's container has no key of its own. Two things about that
478container: a secret with newlines (a private key) arrives intact, and
479=ssh= expands =~= from the passwd entry, =/root=, not from =$HOME=,
480which is the build home — so keep an ssh config in the workspace and
481pass it with =ssh -F= (and =GIT_SSH_COMMAND="ssh -F ..."= for git),
482which also works on a runner with no container, where writing to
483=~/.ssh= would edit that machine's own configuration.
478 484
479Secrets: =repo secret set <owner/name> <NAME>= reads the value from 485Secrets: =repo secret set <owner/name> <NAME>= reads the value from
480stdin (never argv) and injects it into the repo's builds as =$NAME=; 486stdin (never argv) and injects it into the repo's builds as =$NAME=;