chore(ci): improve repository maintenance configuration
- Enable weekly Dependabot updates for GitHub Actions dependencies
- Consolidate duplicate Trivy scans into a single SARIF scan with exit-code gate
- Ignore macOS metadata and locally downloaded drone-ssh binaries
- Add feature request issue template and pull request checklist template
Co-Authored-By: Claude Fable 5 noreply@anthropic.com
版权所有:中国计算机学会技术支持:开源发展技术委员会
京ICP备13000930号-9
京公网安备 11010802047560号
🚀 SSH for GitHub Actions
English | 繁體中文 | 简体中文
Table of Contents
📖 Introduction
SSH for GitHub Actions is a powerful GitHub Action for executing remote SSH commands easily and securely in your CI/CD workflows.
Built with Golang and drone-ssh, it supports a wide range of SSH scenarios, including multi-host, proxy, and advanced authentication.
Slides: SSH for GitHub Actions
🧩 Core Concepts & Input Parameters
This action provides flexible SSH command execution with a rich set of configuration options.
For full details, see action.yml.
🔌 Connection Settings
These parameters control how the action connects to your remote host.
tcp,tcp4,tcp6)~/.ssh/id_rsa)🛠️ SSH Command Settings
These parameters control the commands executed on the remote host and related behaviors.
GITHUB_andINPUT_prefixes to the script🌐 Proxy Settings
These parameters control the use of a proxy (jump host) for connecting to your target host.
📤 Output Variables
This action provides the following outputs that you can use in subsequent steps:
capture_stdout: true)⚡ Quick Start
Run remote SSH commands in your workflow with minimal configuration:
Output:
🔑 SSH Key Setup & OpenSSH Compatibility
Setting Up SSH Keys
It is best practice to create SSH keys on your local machine (not on a remote server). Log in with the username specified in GitHub Secrets and generate a key pair:
Generate RSA key
Generate ED25519 key
Add the new public key to the authorized keys on your server. Learn more about authorized keys.
Copy the private key content and paste it into GitHub Secrets.
For ED25519:
See more: SSH login without a password.
OpenSSH Compatibility
If you see this error:
On Ubuntu 20.04+ you may need to explicitly allow the
ssh-rsaalgorithm. Add this to your OpenSSH daemon config (/etc/ssh/sshd_configor a drop-in under/etc/ssh/sshd_config.d/):Alternatively, use ED25519 keys (supported by default):
🛠️ Usage Scenarios & Advanced Examples
This section covers common and advanced usage patterns, including multi-host, proxy, and environment variable passing.
Using password authentication
Using private key authentication
Multiple commands
Run commands from a file
Multiple hosts
Default
portis22.Multiple hosts with different ports
Synchronous execution on multiple hosts
Pass environment variables to shell script
Capturing command output
You can capture the standard output of remote commands and use it in subsequent steps:
🌐 Proxy & Jump Host Usage
You can connect to remote hosts via a proxy (jump host) for advanced network topologies.
Example
~/.ssh/config:GitHub Actions YAML:
🛡️ Security Best Practices
Protecting Your Private Key
A passphrase encrypts your private key, making it useless to attackers if leaked. Always store your private key securely.
Host Fingerprint Verification
Verifying the SSH host fingerprint helps prevent man-in-the-middle attacks. To get your host’s fingerprint (replace
ed25519with your key type andexample.comwith your host):Update your config:
🚨 Error Handling & Troubleshooting
Q&A
Command not found (npm or other command)
If you encounter “command not found” errors, see this issue comment about interactive vs non-interactive shells.
On many Linux distros,
/etc/bash.bashrccontains:Comment out this line or use absolute paths for your commands.
🤝 Contributing
Contributions are welcome! Please submit a pull request to help improve
appleboy/ssh-action.📝 License
This project is licensed under the MIT License.