24 Commits
Author SHA1 Message Date
wl c392989cc9 Merge pull request #63 from KinNeko-De/feature/62-ssh-private-key-parameter
Make ssh_private_key optional in action.yml
2026-03-24 10:49:31 +08:00
Nils Diekmann bada6e2c24 Make ssh_private_key optional in action.yml
Changed ssh_private_key requirement from true to false.
2025-10-16 14:58:53 +02:00
wl a5ccb9c621 fix: use default value for unset passphrase parameter to prevent error
Update the script to reference the 12th parameter as ${12:-} instead of ${12} when checking for a passphrase. This change prevents the script from failing with a "parameter not set" error under set -u if the passphrase is not provided.
2025-04-16 10:41:35 +08:00
wl b131f3d078 Merge pull request #61 from jreker/master
Added support for encrypted private keys
2025-04-16 10:06:51 +08:00
Johannes Reker a2526c619d doc: refined example and changed versions 2025-03-19 16:53:16 +01:00
Johannes Reker 74f82cb508 feat: added ssh_passphrase for encrypted private key auth 2025-03-19 16:43:23 +01:00
wl 896dcfc555 feat: Add rsync filtering and optimize SFTP deployment process
- Introduced rsync support with customizable `rsyncArgs` for file filtering.
- Ensured only filtered content is uploaded, avoiding `filtered_upload` folder inclusion.
- Updated documentation to reflect the latest changes and usage examples.
2024-12-31 11:39:56 +08:00
wl 89e97d73f9 1. update readme 2023-08-21 14:45:05 +08:00
wl 675755b272 1. Update readme about issues #51 2023-03-17 10:12:18 +08:00
wl 067de34294 Merge pull request #34 from alfreddagenais/master
Ajustement for Readme file
2022-07-14 13:42:29 +08:00
Alfred Dagenais 834e1ad841 CHG: ajustement wording explication 2022-07-13 16:56:43 -04:00
Alfred Dagenais 259119b427 ADD: s 2022-07-13 16:55:23 -04:00
Alfred Dagenais f944ea4c67 CHG: ajustement tab vs spacing 2022-07-13 16:54:30 -04:00
Alfred Dagenais 7589349f24 CHG: ajustement into documentation 2022-07-13 16:49:23 -04:00
wl da88a4dbe9 fix password typo 2022-07-01 09:29:31 +08:00
wl e57406ff6c 1. update readme 2022-07-01 09:26:31 +08:00
wl 6596a6c48c 1. support password 2022-07-01 09:23:58 +08:00
wl 33436f92f1 1. require remote_path 2022-06-29 21:49:29 +08:00
wl 3586e619fa 1. Option to let delete existing files 2022-06-29 20:47:36 +08:00
wl 8392b571c7 Merge pull request #17 from Bunyod545/patch-1
Docker file Alpine version changed to 3.13
2022-06-29 13:31:52 +08:00
wl c6e4d76ad9 Merge pull request #26 from leoppro/master
Add an option named `sftp_only` to connect via sftp only
2022-02-22 08:43:07 +08:00
leoppro 3a6bd36ae1 Add an option named sftp_only to connect via sftp only 2021-09-19 20:50:48 +08:00
Bunyod545 00c712f732 Docker file Alpine version changed to 3.13 2021-06-08 15:53:46 +05:00
wl 28d6168ebf 1. fix mkdir issue 2021-03-31 12:50:09 +08:00
6 changed files with 333 additions and 144 deletions
+26
View File
@@ -0,0 +1,26 @@
name: Continuous Deploy
on: [push]
jobs:
deploy_job:
runs-on: ubuntu-latest
name: sftp
steps:
- name: Checkout
uses: actions/checkout@v2
- name: deploy file to server
uses: ./ # Uses an action in the root directory
with:
username: '${{ secrets.USER }}'
server: '${{ secrets.SERVER_IP }}'
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
local_path: './*'
remote_path: '/tmp/testAction'
sftpArgs: '-o ConnectTimeout=5'
rsyncArgs: '--exclude *.yml'
# sftp_only: true
# password: ${{secrets.SSH_PASSWORD}}
# delete_remote_files: true
+9 -12
View File
@@ -1,15 +1,12 @@
# Container image that runs your code
FROM alpine:3.10
# Use an up-to-date and secure Alpine version
FROM alpine:3.18
# Copies your code file from your action repository to the filesystem path `/` of the container
# Install required packages in one RUN statement to reduce image layers
RUN apk update && apk add --no-cache rsync sshpass openssh expect
# Copy entrypoint script and set correct permissions
COPY entrypoint.sh /entrypoint.sh
RUN chmod +x /entrypoint.sh
#Make sure to make you entrypoint.sh file executable:
RUN chmod 777 entrypoint.sh
RUN apk update
RUN apk add --no-cache openssh
# Code file to execute when the docker container starts up (`entrypoint.sh`)
ENTRYPOINT ["/entrypoint.sh"]
# Set the entrypoint for the container
ENTRYPOINT ["/bin/sh", "/entrypoint.sh"]
+175 -117
View File
@@ -1,132 +1,190 @@
# SFTP Deploy action
> Use this action to deploy your files to server using `SSH Private Key`
# SFTP Deploy Action
> 使用此`action`部署你的项目到服务器上,`仅支持密钥对连接`
> Use this action to deploy your files to a server using `SSH Private Key`
> [使用Github Action 部署项目到云服务器](https://zhuanlan.zhihu.com/p/107545396)
> 使用此 `action` 部署你的项目到服务器上,中文介绍链接:[使用Github Action 部署项目到云服务器](https://zhuanlan.zhihu.com/p/107545396)
---
## 🚀 **1. Inputs**
| Name | Required | Default | Description |
|------------------------|----------|---------|----------------------------------------------------------------------------------------------------------------------|
| `username` | yes | | SSH username |
| `server` | yes | | Remote host |
| `port` | yes | 22 | Remote host port |
| `ssh_private_key` | no | | You can copy the private key from your `ssh_private_key` file and save it to `repo/settings/secrets`<br> ![](./resource/secret.jpg) |
| `local_path` | yes | `./*` | Local path of your project. <br> - Single file: `./myfile` <br> - Directory: `./static/*` <br> Default: `./*` (will put all files in your repo). |
| `remote_path` | yes | | The target folder on the remote server. |
| `sftp_only` | no | | If your port only accepts the sftp protocol, set this option to `true`. However, when set to `true`, the remote folder won't be automatically created. |
| `sftpArgs` | no | | Extra arguments you want to pass to `sftp`, for example: `-o ConnectTimeout=5` |
| `delete_remote_files` | no | false | Set to `true` to delete the remote path folder and all files in it **before** uploading. |
| `password` | no | | SSH password. If a password is set, `ssh_private_key` and `ssh_passphrase` is ignored. *(for @v1.2.4 and greater)* |
| `rsyncArgs` | no | | Additional arguments for the `rsync` command. You can customize file synchronization behavior, such as excluding files or directories. Example: `--exclude=node_modules --exclude=.git --exclude=*.log`. *(for @v1.2.5 and greater)* |
| `ssh_passphrase` | no | | The passphrase for encrypted ssh private-key |
> ⚠️ **Warning:**
> Be careful when using `delete_remote_files`. This will **permanently delete** the remote path folder and all files in it **before** uploading.
---
## 📦 **2. Action Examples**
### **🔹 Basic Example**
```yaml
on: [push]
jobs:
deploy_job:
runs-on: ubuntu-latest
name: Deploy Files
steps:
- name: Checkout
uses: actions/checkout@v2
- name: Deploy to Server
uses: wlixcc/SFTP-Deploy-Action@v1.2.6
with:
username: 'root'
server: 'your server ip'
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
local_path: './static/*'
remote_path: '/var/www/app'
sftpArgs: '-o ConnectTimeout=5'
```
---
### **🔹 Example with rsyncArgs**
```yaml
on: [push]
jobs:
deploy_job:
runs-on: ubuntu-latest
name: Deploy with rsync exclude
steps:
- name: Checkout
uses: actions/checkout@v2
- name: Deploy with Exclude Patterns
uses: wlixcc/SFTP-Deploy-Action@v1.2.6
with:
username: 'root'
server: 'your server ip'
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
local_path: './'
remote_path: '/var/www/app'
rsyncArgs: '--exclude=node_modules --exclude=.git --exclude=*.log'
sftpArgs: '-o ConnectTimeout=5'
```
---
### **🔹 Example with Password Authentication**
```yaml
on: [push]
jobs:
deploy_job:
runs-on: ubuntu-latest
name: Deploy with Password
steps:
- name: Checkout
uses: actions/checkout@v2
- name: Deploy with Password
uses: wlixcc/SFTP-Deploy-Action@v1.2.6
with:
username: ${{ secrets.FTP_USERNAME }}
server: ${{ secrets.FTP_SERVER }}
port: ${{ secrets.FTP_PORT }}
local_path: './static/*'
remote_path: '/var/www/app'
sftp_only: true
password: ${{ secrets.FTP_PASSWORD }}
```
## Inputs
### **🔹 Example with Encrypted Private Key Authentication**
```yaml
on: [push]
### `username`
jobs:
deploy_job:
runs-on: ubuntu-latest
name: Deploy with encrypted private key
steps:
- name: Checkout
uses: actions/checkout@v2
**Required** sftp username.
- name: Deploy with encrypted private key
uses: wlixcc/SFTP-Deploy-Action@v1.2.6
with:
username: ${{ secrets.FTP_USERNAME }}
server: ${{ secrets.FTP_SERVER }}
port: ${{ secrets.FTP_PORT }}
local_path: './static/*'
remote_path: '/var/www/app'
sftp_only: true
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
ssh_passphrase: ${{ secrets.SSH_PASSPHRASE }}
```
---
### `server`
## 🌐 **3. [Deploy React App Example](https://github.com/wlixcc/React-Deploy)**
**Required** sftp server address.
```yaml
on: [push]
### `port`
jobs:
deploy_job:
runs-on: ubuntu-latest
name: Build & Deploy React App
steps:
- name: Checkout
uses: actions/checkout@v2
sftp srever port , default `22`
- name: Install Dependencies
run: yarn
### `ssh_private_key`
- name: Build
run: yarn build
**Required** you can copy private_key from your `ssh_private_key.pem file`, keep format, and save at`repo/settings/secrets`
- name: Deploy Build Folder
uses: wlixcc/SFTP-Deploy-Action@v1.2.6
with:
username: 'root'
server: '${{ secrets.SERVER_IP }}'
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
local_path: './build/*'
remote_path: '/var/www/react-app'
rsyncArgs: '--exclude=*.map'
sftpArgs: '-o ConnectTimeout=5'
```
![](./resource/reactExample.jpg)
---
## 🛡️ **4. Invalid format? You need to keep the format**
If you use the **Ed25519** algorithm to generate an SSH key pair:
```sh
ssh-keygen -t ed25519 -C "your_email@example.com"
```
⚠️ **Important:**
The last line of the private key **must remain a blank line** when adding it to **Repository Secrets**.
If you remove it, you might encounter an `invalid format` error.
![](./resource/keepformat.jpg)
---
![](./resource/secret.jpg)
### `local_path`
**Required** `local_path` of you project, if you want put single file:use path like `./myfile`, if you want put directory: use path like `./static/*`, it will put all files under `static` directory. Default to `./*`(will put all files in your repo).
### `remote_path`
**Required** remote_path
### `args`
args of sftp cmd, E.g.`-o ConnectTimeout=5`
## Action Example
on: [push]
jobs:
deploy_job:
runs-on: ubuntu-latest
name: deploy
steps:
- name: Checkout
uses: actions/checkout@v2
- name: deploy file
uses: wlixcc/SFTP-Deploy-Action@v1.0
with:
username: 'root'
server: 'your server ip'
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
local_path: './static/*'
remote_path: '/var/www/app'
args: '-o ConnectTimeout=5'
## 1. [Deploy React App Example](https://github.com/wlixcc/React-Deploy)
> If you use nginx, all you need to do is upload the static files to the server after the project is built
on: [push]
jobs:
deploy_job:
runs-on: ubuntu-latest
name: build&deploy
steps:
# To use this repository's private action, you must check out the repository
- name: Checkout
uses: actions/checkout@v2
- name: Install Dependencies
run: yarn
- name: Build
run: yarn build
- name: deploy file to server
uses: wlixcc/SFTP-Deploy-Action@v1.0
with:
username: 'root'
server: '${{ secrets.SERVER_IP }}'
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
local_path: './build/*'
remote_path: '/var/www/react-app'
args: '-o ConnectTimeout=5'
![](./resource/reactExample.jpg)
## 2.Deploy Umi App Example (Ant Design Pro)
name: continuous deployment
on: [push]
jobs:
deploy_job:
runs-on: ubuntu-latest
name: build&deploy
steps:
# To use this repository's private action, you must check out the repository
- name: Checkout
uses: actions/checkout@v2
- name: Install umi
run: yarn global add umi
- name: Install Dependencies
run: yarn
- name: Build
run: yarn build
- name: deploy file to server
uses: wlixcc/SFTP-Deploy-Action@v1.0
with:
username: 'root'
server: '${{ secrets.SERVER_IP }}'
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
local_path: './dist/*'
remote_path: '/var/www/umiapp'
args: '-o ConnectTimeout=5'
![](./resource/umiExample.jpg)
+30 -6
View File
@@ -14,7 +14,7 @@ inputs:
default: "22"
ssh_private_key:
description: 'you can copy private_key from your *.pem file, keep format'
required: true
required: false
local_path:
description: 'will put all file under this path'
required: true
@@ -22,12 +22,30 @@ inputs:
remote_path:
description: 'files will copy to under remote_path'
required: true
default: /
args:
sftp_only:
description: 'connection via sftp protocol only'
required: false
default: false
sftpArgs:
description: 'sftp args'
required: false
delete_remote_files:
description: 'This operation will delete all files in the remote path before upload. Please be careful set this to true'
required: false
default: false
password:
description: "SSH passswordIf a password is set, the secret key pair is ignored"
required: false
rsyncArgs:
description: "Additional arguments for the rsync command.
You can use this parameter to customize the rsync behavior, such as excluding files or directories.
Example: '--exclude=node_modules --exclude=.git --exclude=*.log'.
If set, these arguments will be passed directly to the rsync command."
required: false
default: ""
ssh_passphrase:
description: "Passphrase for ssh encrypted private-key. If the private-key is not encrypted, this parameter is not required."
required: false
runs:
using: 'docker'
@@ -39,7 +57,13 @@ runs:
- ${{ inputs.ssh_private_key }}
- ${{ inputs.local_path }}
- ${{ inputs.remote_path }}
- ${{ inputs.args }}
- ${{ inputs.sftp_only }}
- ${{ inputs.sftpArgs }}
- ${{ inputs.delete_remote_files }}
- ${{ inputs.password }}
- ${{ inputs.rsyncArgs }}
- ${{ inputs.ssh_passphrase }}
branding:
icon: 'upload-cloud'
+93 -9
View File
@@ -3,28 +3,112 @@
#set -e at the top of your script will make the script exit with an error whenever an error occurs (and is not explicitly handled)
set -eu
TEMP_SSH_PRIVATE_KEY_FILE='../private_key.pem'
TEMP_SFTP_FILE='../sftp'
# 定义一个本地临时目录,用于 rsync 过滤后存放文件
RSYNC_LOCAL_DEST="../filtered_upload"
RSYNC_ARGS="${11}"
# 如果用户“未”设置 excludeEXCLUDE_PATTERNS 为空),则直接进入原逻辑
if [ -z "$RSYNC_ARGS" ]; then
echo "===> No rsync args provided, skip rsync filtering..."
else
echo "===> rsync args detected, start rsync filtering..."
# 先清理并创建该临时目录
rm -rf "$RSYNC_LOCAL_DEST"
mkdir -p "$RSYNC_LOCAL_DEST"
# 6) 打印完整的 rsync 命令,方便调试
echo "===> rsync command: rsync -av $RSYNC_ARGS $5 $RSYNC_LOCAL_DEST/"
# 执行 rsync 命令
rsync -av $RSYNC_ARGS $5 $RSYNC_LOCAL_DEST/
# 将 $5 替换为过滤后的目录下的所有文件,这样后面原脚本里 put -r $5 $6 就无需改动其他地方
set -- "$1" "$2" "$3" "$4" "$RSYNC_LOCAL_DEST/*" "$6" "$7" "$8" "$9" "${10}"
echo "===> Done rsync filtering. Continue original script..."
fi
# make sure remote path is not empty
if [ -z "$6" ]; then
echo 'remote_path is empty'
exit 1
fi
# use password
if [ -n "${10}" ]; then
echo 'use sshpass'
if test $9 == "true";then
echo 'Start delete remote files'
sshpass -p ${10} ssh -o StrictHostKeyChecking=no -p $3 $1@$2 rm -rf $6
fi
if test $7 = "true"; then
echo "Connection via sftp protocol only, skip the command to create a directory"
else
echo 'Create directory if needed'
sshpass -p ${10} ssh -o StrictHostKeyChecking=no -p $3 $1@$2 mkdir -p $6
fi
echo 'SFTP Start'
# create a temporary file containing sftp commands
printf "%s" "put -r $5 $6" >$TEMP_SFTP_FILE
#-o StrictHostKeyChecking=no avoid Host key verification failed.
SSHPASS=${10} sshpass -e sftp -oBatchMode=no -b $TEMP_SFTP_FILE -P $3 $8 -o StrictHostKeyChecking=no $1@$2
echo 'Deploy Success'
exit 0
fi
# keep string format
printf "%s" "$4" >$TEMP_SSH_PRIVATE_KEY_FILE
# avoid Permissions too open
chmod 600 $TEMP_SSH_PRIVATE_KEY_FILE
echo 'ssh start'
# delete remote files if needed
if test $9 == "true";then
echo 'Start delete remote files'
ssh -o StrictHostKeyChecking=no -p $3 -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2 rm -rf $6
fi
ssh -o StrictHostKeyChecking=no -p $3 -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2
if test $7 = "true"; then
echo "Connection via sftp protocol only, skip the command to create a directory"
else
echo 'Create directory if needed'
ssh -o StrictHostKeyChecking=no -p $3 -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2 mkdir -p $6
fi
# create directory if needed
mkdir -p $6
# check if passphrase is set, if yes decrypt the private key
if [ -n "${12:-}" ]; then
echo 'Use ssh-agent to decrypt private key with passphrase'
# start ssh agent
eval $(ssh-agent -s)
# use expect for ssh passphrase encryption
expect <<EOF
spawn ssh-add $TEMP_SSH_PRIVATE_KEY_FILE
expect "Enter passphrase"
send "${12}\r"
expect eof
EOF
fi
echo 'sftp start'
echo 'SFTP Start'
# create a temporary file containing sftp commands
printf "%s" "put -r $5 $6" >$TEMP_SFTP_FILE
#-o StrictHostKeyChecking=no avoid Host key verification failed.
sftp -b $TEMP_SFTP_FILE -P $3 $7 -o StrictHostKeyChecking=no -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2
sftp -b $TEMP_SFTP_FILE -P $3 $8 -o StrictHostKeyChecking=no -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2
echo 'Deploy Success'
# if passphrase is set stop ssh-agent after sftp connection
if [ -n "${12:-}" ]; then
echo 'Clear keys from ssh-agent'
# delete all keys from RAM
ssh-add -D
fi
echo 'deploy success'
exit 0
Binary file not shown.

After

Width:  |  Height:  |  Size: 54 KiB