.gitbay/bot-ssh.sh
16 lines · 820 bytes
1# Sourced by pages.sh and release.sh. The build runs in a container that
2# holds no key of its own; the orgo-ci account's private key (write on this
3# repository) arrives as the BOT_SSH_KEY secret and is written into the
4# workspace beside an ssh config every ssh and git call is pointed at with
5# -F. GITBAY_SSH, set by the runner, is the instance as this build reaches
6# it. Nothing is written outside the workspace.
7: "${BOT_SSH_KEY:?BOT_SSH_KEY secret is not set}"
8: "${GITBAY_SSH:?GITBAY_SSH is not set; the runner is too old}"
9(
10 umask 077
11 printf '%s\n' "$BOT_SSH_KEY" >"$PWD/.bot_key"
12 printf 'IdentityFile %s\nIdentitiesOnly yes\nStrictHostKeyChecking accept-new\nUserKnownHostsFile %s\n' \
13 "$PWD/.bot_key" "$PWD/.known_hosts" >"$PWD/.ssh_config"
14)
15SSH="ssh -F $PWD/.ssh_config"
16export GIT_SSH_COMMAND="$SSH"