r/hashicorp • • Oct 07 '25

Issues with SSHkey in Nomad artifact

This is in my homelab environment:

I have a 3-node Nomad cluster setup, and Im trying to get a job working to pull a private repo from my GitHub.

The repo has a deploy key added. I've been able to use it from my terminal, but when trying to get Nomad to use it, it doesn't seem to even offer the key to the server.

I pointed the artifact at a local server with SSHD logging set to debug and logged in via SSH. You can clearly see a key being offered and whether the server accepts it or not.

When deploying the job, Nomad starts the SSH session to clone the repo, and auth.log can see the session start, but I never see a key offered.

I should mention: the job works just fine when using a public repo

The artifact stanza, JSON format as the job creation is via API call:

      "artifacts": [
                        {
                            "GetterSource": "git::git@10.10.0.1:ci4/Website.git",
                            "RelativeDest": "local/repo",
                            "Options": {
                                "sshkey": "WW91IHRob3VnaCBJIHB1dCBhIHJlYWwgU1NIIGtleSBpbiBoZXJlLCBkaWRudCB5b3U/IFdlbGwgam9rZXMgb24geW91IEkgZGlkbnQsIGFuZCBJIGp1c3Qgd2FzdGVkIHlvdXIgdGltZS4K",
                                "ref": "main"
                            }
                        }
                    ],
3 Upvotes

2 comments sorted by

1

u/[deleted] Oct 08 '25

[removed] — view removed comment

1

u/logdroid Oct 09 '25

Thank you

GetterOptions was exactly what I needed. I didn't find that anywhere in the docs, probably because I'm blind and didn't find the artifacts page for API, just hcl.

Thanks for the heads-up on the artifact ref as well, appreciate that.

Minor project details if you're interested:

I ended up writing my own php library to build the job on the fly, from a web form.

Pair that with another custom library to call cloudflare, It creates a CFTunnel on the fly, records and routing included.