fix: log warning when SSH host key verification is disabled#154
Merged
creydr merged 3 commits intoMay 20, 2026
Conversation
When InsecureIgnoreHostKey is used (either because no SSH credentials are provided or because known_hosts data is missing from the auth secret), log an informational message so operators can identify and remediate insecure configurations.
The previous commit removed the InsecureIgnoreHostKey fallback when an SSH key is provided without known_hosts data, causing E2E failures with "knownhosts: key is unknown".
def202b to
079edc1
Compare
…ring them When a user provides known_hosts data in the auth secret, errors during temp file creation, writing, or callback setup were silently swallowed, causing silent fallback to no host key verification. Now these errors are returned so the operator knows when known_hosts setup fails.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
InsecureIgnoreHostKeyis used for SSH connectionsknown_hostsdata is missingcontext.ContextthroughgetClientOptionsandgetSSHClientOptionsto enable controller-runtime loggingNote: This PR is based on #152 and should be merged after it.