fix(TST-25,SEC): stop CI SSH key leaking in cleartext CI logs
ci / portable (push) Successful in 7m28s
ci / java (push) Successful in 1m59s
ci / nightly-windev (push) Has been skipped
ci / windows-x86 (push) Successful in 1m6s

The windows-x86 acceptance check 'no key material in logs' failed: run #37's
job log printed the full WINDEV_SSH_KEY PEM in the step env echo. Gitea's
secret masker is line-oriented, so a multiline PEM rendered as one line with
literal \n escapes never matches the real-newline secret value and is not
redacted.

Fix: store WINDEV_SSH_KEY base64-encoded (single line) so the masker redacts
it to ***; run-windev-ci.sh auto-decodes a base64 PEM (still accepts a raw PEM
for local hand-testing). Drop the redundant WINDEV_SSH_KNOWN_HOSTS from the job
env (host keys are public and come from the committed windev.known_hosts pin),
removing another cleartext env line. Document the base64 requirement in the
bring-up README.

Operationally: the previously-exposed CI key has been rotated on windev
(old pubkey revoked from administrators_authorized_keys, new key installed) and
the Gitea WINDEV_SSH_KEY secret replaced with the new key's base64.
This commit is contained in:
Joseph Doherty
2026-07-13 10:45:16 -04:00
parent b42cbd0730
commit 6803bab79a
3 changed files with 30 additions and 9 deletions
+8 -4
View File
@@ -31,10 +31,14 @@ first, then merge.
personal windev key): `ssh-keygen -t ed25519 -f ci_windev -N ''`. Append `ci_windev.pub`
to the windev CI account's `authorized_keys` (optionally with a forced `command=` limiting
it to this bootstrap).
3. **Gitea repo secrets** — store the private key as `WINDEV_SSH_KEY` and, optionally, the
pinned host keys as `WINDEV_SSH_KNOWN_HOSTS` (the committed `windev.known_hosts` is the
fallback). `run-windev-ci.sh` connects as user `ci` by default (`WINDEV_SSH_USER` to
override); ensure that account exists on windev, or set `WINDEV_SSH_USER` to the intended one.
3. **Gitea repo secret `WINDEV_SSH_KEY`** — store the private key **base64-encoded on a single
line**: `base64 -w0 < ci_windev` (macOS: `base64 < ci_windev | tr -d '\n'`). This is required,
not cosmetic — Gitea's secret masker is line-oriented, so a raw multiline PEM is **not**
redacted in the step `env:` echo and leaks in cleartext; the single-line base64 masks to `***`.
`run-windev-ci.sh` auto-decodes it. Host keys are public and come from the committed
`windev.known_hosts` pin, so no `WINDEV_SSH_KNOWN_HOSTS` secret is wired into `ci.yml`.
`run-windev-ci.sh` connects as user `ci` by default; set the `WINDEV_SSH_USER` **variable**
(not a secret — it is public) to the actual account, and ensure that account exists on windev.
4. **Network precheck** — confirm the Gitea runner container (on the `traefik` docker network,
host `10.100.0.35`) can reach `10.100.0.48:22`: a one-off `nc -z -w5 10.100.0.48 22` step.
The network was created for gitea name resolution, not LAN egress, so verify.