3 ms·
IMHO, It should break the CI systems. If you don't pre-bake the known-hosts, then you'd allow each new ephemeral run to use whatever github tells you it's key
by stn_za 4y ago
IMHO, It should break the CI systems.
If you don't pre-bake the known-hosts, then you'd allow each new ephemeral run to use whatever github tells you it's key is.
It did briefly break ours, as we pre-bake the known_hosts file into our CI image for convenience and security.
Convenience due to CI not having TTY's, so various tools would get stuck on prompt Y when connecting to github for the first time. (Which is every run, if you are ephemeral CI)
And security, as now everything broke due to github's key changing, which is the desired outcome actually.
We bumped the known_host key entry, merged and all is well again...
- computerfriend 4y agoYou could query GitHub's meta API for the host keys, which is trusting GitHub's HTTPS certificate instead.
- execveat 4y agoYou shouldn't start with a blank state, instead you should be querying https://api.github.com/meta https://api.github.com/meta . But there are so many repos on Github itself which hardcode the host keys in Github Actions, etc.