wiki: ssh's home inside a build container !364
1 file changed, +7 −1
Layout: unified · split
.gitbay/wiki/Users.org +7 −1
| @@ -474,7 +474,13 @@ from a runner elsewhere; inside a container on the server's own runner | |||
| 474 | the host is at a private address the runner fills in). A job that | 474 | the host is at a private address the runner fills in). A job that |
| 475 | talks back to the instance — a release asset, a comment, a push to a | 475 | talks back to the instance — a release asset, a comment, a push to a |
| 476 | pages branch — uses =$GITBAY_SSH= with a key it holds as a secret; | 476 | pages branch — uses =$GITBAY_SSH= with a key it holds as a secret; |
| 477 | the build's container has no key of its own. | 477 | the build's container has no key of its own. Two things about that |
| 478 | container: a secret with newlines (a private key) arrives intact, and | ||
| 479 | =ssh= expands =~= from the passwd entry, =/root=, not from =$HOME=, | ||
| 480 | which is the build home — so keep an ssh config in the workspace and | ||
| 481 | pass it with =ssh -F= (and =GIT_SSH_COMMAND="ssh -F ..."= for git), | ||
| 482 | which also works on a runner with no container, where writing to | ||
| 483 | =~/.ssh= would edit that machine's own configuration. | ||
| 478 | 484 | ||
| 479 | Secrets: =repo secret set <owner/name> <NAME>= reads the value from | 485 | Secrets: =repo secret set <owner/name> <NAME>= reads the value from |
| 480 | stdin (never argv) and injects it into the repo's builds as =$NAME=; | 486 | stdin (never argv) and injects it into the repo's builds as =$NAME=; |