runner: -identity ignores the user's ssh config !365

merged merged by cmc on 2026-09-10 03:47 UTC · krz/gitbay:runner-own-identity into main

2 files changed, +12 −6

Layout: unified · split

cmd/gitbay-runner/config.go +7 −3
@@ -84,11 +84,15 @@ func applyConfig(fs *flag.FlagSet, values map[string]string) error {
84} 84}
85 85
86// identityOpts is what makes ssh and git use the runner's own key and no 86// identityOpts is what makes ssh and git use the runner's own key and no
87// other: on a laptop the ambient key is the user's full-scope one, which 87// other. On a laptop the user's ~/.ssh/config names their full-scope key
88// the runner protocol refuses. 88// for the instance, and IdentitiesOnly keeps identities from the config,
89// so the runner would authenticate as that key and, on an admin's
90// machine, claim every repository's builds. -F /dev/null drops the
91// config; known_hosts is unaffected, and a host seen for the first time
92// is accepted, since a service cannot answer a prompt.
89func identityOpts(path string) []string { 93func identityOpts(path string) []string {
90 if path == "" { 94 if path == "" {
91 return nil 95 return nil
92 } 96 }
93 return []string{"-i", path, "-o", "IdentitiesOnly=yes"} 97 return []string{"-F", "/dev/null", "-i", path, "-o", "IdentitiesOnly=yes", "-o", "StrictHostKeyChecking=accept-new"}
94} 98}
cmd/gitbay-runner/config_test.go +5 −3
@@ -4,6 +4,7 @@ import (
4 "flag" 4 "flag"
5 "os" 5 "os"
6 "path/filepath" 6 "path/filepath"
7 "strings"
7 "testing" 8 "testing"
8) 9)
9 10
@@ -77,8 +78,9 @@ func TestIdentityOpts(t *testing.T) {
77 if got := identityOpts(""); got != nil { 78 if got := identityOpts(""); got != nil {
78 t.Fatalf("empty identity produced %v", got) 79 t.Fatalf("empty identity produced %v", got)
79 } 80 }
80 got := identityOpts("/k") 81 got := strings.Join(identityOpts("/k"), " ")
81 if len(got) != 4 || got[0] != "-i" || got[1] != "/k" || got[3] != "IdentitiesOnly=yes" { 82 want := "-F /dev/null -i /k -o IdentitiesOnly=yes -o StrictHostKeyChecking=accept-new"
82 t.Fatalf("got %v", got) 83 if got != want {
84 t.Fatalf("got %q, want %q", got, want)
83 } 85 }
84} 86}