mirror of
https://github.com/wlixcc/SFTP-Deploy-Action.git
synced 2026-10-03 01:41:31 +00:00
feat: added ssh_passphrase for encrypted private key auth
This commit is contained in:
1 parent
896dcfc555
commit
74f82cb508
4 files changed
+53
-3
No files matched your search
@@ -83,6 +83,20 @@ else
|
||||
ssh -o StrictHostKeyChecking=no -p $3 -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2 mkdir -p $6
|
||||
fi
|
||||
|
||||
# check if passphrase is set, if yes decrypt the private key
|
||||
if [ -n "${12}" ]; then
|
||||
echo 'Use ssh-agent to decrypt private key with passphrase'
|
||||
# start ssh agent
|
||||
eval $(ssh-agent -s)
|
||||
# use expect for ssh passphrase encryption
|
||||
expect <<EOF
|
||||
spawn ssh-add $TEMP_SSH_PRIVATE_KEY_FILE
|
||||
expect "Enter passphrase"
|
||||
send "${12}\r"
|
||||
expect eof
|
||||
EOF
|
||||
fi
|
||||
|
||||
echo 'SFTP Start'
|
||||
# create a temporary file containing sftp commands
|
||||
printf "%s" "put -r $5 $6" >$TEMP_SFTP_FILE
|
||||
@@ -90,4 +104,11 @@ printf "%s" "put -r $5 $6" >$TEMP_SFTP_FILE
|
||||
sftp -b $TEMP_SFTP_FILE -P $3 $8 -o StrictHostKeyChecking=no -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2
|
||||
|
||||
echo 'Deploy Success'
|
||||
# if passphrase is set stop ssh-agent after sftp connection
|
||||
if [ -n "${12}" ]; then
|
||||
echo 'Clear keys from ssh-agent'
|
||||
# delete all keys from RAM
|
||||
ssh-add -D
|
||||
fi
|
||||
|
||||
exit 0
|
||||
Reference in new issue
Block a user