5 ms·
Launch a Debugging Terminal into GitHub Actions
- lawrencegripper 9mo agoAuthor here, this was something I wrote for fun/because I wanted to use it. Happy to answer any questions
- Imustaskforhelp 9mo agoThis is really awesome and I might try it (definitely bookmarked) This might seem (offtopic?) but you mention railway and how for a 20mb app the costs become almost negligible and I got curious because I usually refer hetzner to be one of the cheapest but still good/well worthy solution I find the pricing model of railway the most interesting. I am curious if you know of any other alternatives to railway which follow a similar pricing model as well as I'd like to compare if there are more of such cloud providers which provide this (preferably from a service which is more closer to bare metal than y'know cloud providers perhaps if that makes sense)
- lawrencegripper 9mo agoThanks! I'm not aware of others offering this pricing model
- dreslan 9mo agoI love this use of hole punching, also love how the author handled authentication. I have definitely been in the position of needing to tweak a workflow over and over to get it to work, wasting hours when a terminal into the action would have allowed me to close the loop in minutes. Nice work to the author!
- whynotmaybe 9mo agoThat's my hill to die on : you must have a self hosted agent. You can have many cloud agents as you wish but you must at least have one where you can remotely connect. It has saved me hours of troubleshooting and polluting "workflow v1.3.56_final_should_work_2" commits
- nwellinghoff 9mo agoAgreed. So much easier with self hosted runner. Just get out of your own way and do it. Use cases like caching etc also much more efficient on self hosted runner.
- flanked-evergl 9mo agoThis kind of misses the point, though. I would say a much better rule is whatever runs in your workflows should also be entirely reproducible locally. Even if you can ssh into the remote environment that does not cover things like authentication and authorization, you don't just git a GITHUB_TOKEN with the same permissions.
- Storment33 9mo agoExactly, you should be able to do everything locally! All this needing to SSH into runners or needing self-hosted runners or needing act to emulate GitHub Actions is really a failure of the developer experience.
- whynotmaybe 9mo agoA lot of stuff can be handled by developer themselves, but usually some steps are voluntarily blocked, like publishing to Google Play/App store. You don't want anyone to be able to publish public facing app from their version of the code that might not be committed. Some of us remember an era where deployment was copy-paste from the local /bin folder to the /bin folder on production server.
- Storment33 9mo agoWhile I get some stuff you can't test locally, like 90%+ of complaints I see are for builds/tests. Which is really a failure of the engineers for not having a local feedback loop. I am of the opinion you should be able to deploy from your machine, just you do not have the permissions to normally. So that if CI ever goes down and you need to push an emergency fix or something you can break glass if needed.
- baby_souffle 9mo agoThere are many tools and techniques like this. Not a nock against this tool, just an observation that we seemingly need these tools. Is there no better way, GitHub?
- embedding-shape 9mo ago> Is there no better way, GitHub? CircleCI solved this anno 2011, with "Rebuild with SSH". Microsoft asleep at the wheel as usual, not sure it's unexpected at this point.
- bathtub365 9mo agoThe more you have to rerun your actions to debug them, the more money Microsoft makes. They aren’t incentivized to save you time.
- embedding-shape 9mo agoCompletely bonkers that people, companies and organizations just swallow this, bait and all.
- esafak 9mo agoFree hosting, CI minutes, and an ecosystem.
- embedding-shape 9mo agoCommit and push to test small incremental changes, self-hosted runners' time still count towards CI minutes, and an ecosystem hellbent on presenting security holes as new features. I'm a bit unimpressed :)
- esafak 9mo agoDagger. Workflows that run anywhere, including locally.
- stabbles 9mo agoI'm using tmate for this: https://github.com/mxschmitt/action-tmate https://github.com/mxschmitt/action-tmate
- Etheryte 9mo agoThis is the only reasonable way to ever do this, requires no effort, just copy paste one of the examples and you're done. My only gripe is that the most secure option isn't the first example in the repo. Limit access to the actor and put it behind the debug only flag and you're good to go. Still, I remove it after the fact once I don't need it anymore since it feels a bit too sketch with secrets available.
- gorjusborg 9mo agoI'll second this. I've used this action to debug builds, and it works beautifully. However, I've had to stop because the action isn't a 'verified' action and corporate policy. I'd love to see github themselves offer something like this.
- SamuelAdams 9mo agoThe neat part is you can do whatever you want in a GitHub action, corporate policy be damned. So: git clone <tmate / banned action git URL> cd <the action> Run the action start point. Apparently this is a feature, not a security risk. https://blog.yossarian.net/2025/06/11/github-actions-policies-dumb-bypass https://blog.yossarian.net/2025/06/11/github-actions-policie...
- theK 9mo agotmate.io returns a 503. Hugged to death by your comment?
- efrecon 9mo agoI have written https://github.com/efrecon/sshd-cloudflared https://github.com/efrecon/sshd-cloudflared to solve the same problem. It provides you with an SSH connection inside a transient cloudflare tunnel. The connection is only accessible to the SSH public keys stored in your GitHub account.
- embedding-shape 9mo agoThat the entire ecosystem seems to have moved to GitHub Actions is such a loss for productivity. I remember when CircleCI first launched, and you could "Rebuild with SSH" which gave you a bash command to connect to the running instance whenever you wanted, was such a no-brainer, and I'm sure why many of us ended up using CircleCI for years. Eventually CircleCI became too expensive, but I still thought that if other services learnt anything from CircleCI, it would be this single feature, because of the amount of hours it saved thousands of developers. Lo and behold, when GitHub Actions first launched, that feature was nowhere to be seen, and I knew from that moment on that betting on GitHub Actions would be a mistake, if they didn't launch with such a table-stakes feature. Seems still Microsoft didn't get their thumb out, and wasting countless developer's time with this, sad state of affairs. Thank you pbiggar for the time we got with CircleCI :) Here's to hoping we'll have CircleCI.V2 appearing at some point in the future, I just know it involves DAGs and "Rebuild with SSH" somehow :)
- kevmo314 9mo agoI am surprised Docker didn't launch into the CI market. Running a container build as CI seems like it would both be a boon for simplifying CI caching and also debugging since it's ~reproducible locally.
- hobofan 9mo agoThey _are_ in the CI market. Two of their products are the Docker Build Cloud and Testcontainers Cloud. IIRC Docker Hub also came with automated builds at some point (not sure if it still does). I do get your sentiment tough. For the position they are in, a CircleCI-like product would seem to be quite fitting.
- kevmo314 9mo agoWow you're right they are. Yeah, they could really use some improvement there. https://docs.docker.com/build-cloud/ci/ https://docs.docker.com/build-cloud/ci/ This could've been a "change runs-on to be this" like all the other faster GHA startup products, but instead the way they set it up I would have to keep paying for GHA while also paying for their build cloud. No fun!
- franktankbank 9mo agoWhen I see stuff like this, I think wow that is cool. But then I think about doing it myself and I get nervous about security ramifications. I don't know enough myself to know if author knows the right way ya know??
- msie 9mo agoI gave GH actions a chance when our org moved from Bamboo but I still hate it. I think i have to do more to get a build going.
- axm__ 9mo agoI was looking at frp for this. Setup is a bit more involved but you don't need a browser terminal: https://github.com/rgl/frp-github-actions-reverse-shell https://github.com/rgl/frp-github-actions-reverse-shell
- stets 9mo agoI want this for Gitlab so badly
- Mogzol 9mo agoGitLab already has "interactive web terminals" which is basically the same thing: https://docs.gitlab.com/ci/interactive_web_terminal/ https://docs.gitlab.com/ci/interactive_web_terminal/
- cyberax 9mo agoI solved it by adding a simple Tailscale action to handle failure. It creates an ephemeral instance and waits for connections for 3 minutes. Then it loops while there's an active SSH session present. It's that simple: https://gist.github.com/Cyberax/9edbde51380bf7e1b298245464a24c55 https://gist.github.com/Cyberax/9edbde51380bf7e1b298245464a2... and it saved me _hours_ of debug time. I've moved all my CI/CD to use Taskfiles inside a Docker container since then, so my local environment can replicate the CI/CD environment up to the GITHUB_TOKEN. Still, being able to poke around Github builders is great.
- lioeters 9mo agoThat looks like a useful trick, using an ephemeral instance to SSH into a failed CI action context. I see in the script how it waits and checks for root user login, but to keep it alive, this part: > Then it loops while there's an active SSH session present. From what I can see, the loop stops when a user is logged in. Is this handled elsewhere? > use Taskfiles inside a Docker container since then, so my local environment can replicate the CI/CD environment Oh this is what I've been wanting, a vendor-neutral way to run the same CI actions locally. I'd seen go-task before, will try it, thanks for the info!
- cyberax 9mo ago> That looks like a useful trick, using an ephemeral instance to SSH into a failed CI action context. Yup. And Tailscale even manages the SSH key provisioning. > From what I can see, the loop stops when a user is logged in. Is this handled elsewhere? The script does handle it. The `pgrep` succeeds (returns zero exit code) if there's a "login" process for user 'root' present, which is created when there's an active SSH session. If pgrep fails, then `break` runs and exits the loop. Github then terminates the workflow and releases the runner.
- lioeters 9mo agoAh I see what you mean, the loop keeps it alive until login is detected, and after that the machine is kept alive by the SSH session itself. Appreciated.
- t_tsonev 9mo agoWhy SSH to the build agent when you can run your actions locally using the excellent https://github.com/nektos/act https://github.com/nektos/act
- hole_in_foot 9mo ago[dead]
- apwheele 9mo agoI only have pretty tame actions workflows and I have had a hard time replicating simple set ups with this. I can't imagine a company with more complicated setups. What I wish is github codespaces could just do this out of the box, at least for a specific action/runner.
- x0rg 9mo agoWow that's great, I'm definitely going to try it. This guy knows what he is doing.
- theknarf 9mo agoI remember when https://sshx.io/ https://sshx.io/ first launched for this use case