We're using the ssh-run pipe to execute a build step on a remote machine.
This build step needs access to secrets which we have defined as "secured" bitbucket workspace variables.
When running the ssh-run pipe, the content of one of those variables is printed in plain text, however.
This is what the relevant parts of our bitbucket-pipelines.yml looks like:
image: atlassian/default-image:2
pipelines:
branches:
develop:
- step:
name: Deploy to test
deployment: Test
script:
- pipe: atlassian/ssh-run:0.4.2
variables:
SSH_USER: $BUILD_USER
SERVER: $BUILD_SERVER
PORT: $BUILD_SSH_PORT
SSH_KEY: $BITBUCKET_CI_SSH_KEY
MODE: "script"
COMMAND: "tools/ci-deploy.sh"
ENV_VARS: >-
GCP_WRITER_JSON='${GCP_WRITER_JSON}'
REMOTE_CI_SSH_KEY='${REMOTE_CI_SSH_KEY}'
During setup of the step, the command
docker container run ... bitbucketpipelines/ssh-run:0.4.2
does not reveal the content of the secret variables.
But when that pipe executes the actual SSH command
<span>ssh -i /root/.ssh/pipelines_id ... GCP_WRITER_JSON='<THE CONTENT IN PLAIN TEXT>' REMOTE_CI_SSH_KEY='<THE CONTENT IS HIDDEN>'</span>
the variable content is visible in the pipeline log.
This is problematic. Can this be avoided by defining the pipeline differently?
EDIT:
I suspect this has something to do with the content of the GCP_WRITER_JSON variable. It looks as follows
{ "type": "service_account", "project_id": "my-container-registry", "private_key_id": "...", "private_key": "-----BEGIN PRIVATE KEY-----...-----END PRIVATE KEY-----\n", "client_email": "...@my-container-registry.iam.gserviceaccount.com", "client_id": "...", "auth_uri": "...", "token_uri": "...", "auth_provider_x509_cert_url": "...", "client_x509_cert_url": "...",}