finds.dev← search

// the find

appleboy/ssh-action

★ 6,216 · Shell · MIT · updated Aug 2026

GitHub Actions for executing remote ssh commands.

A GitHub Action that wraps appleboy/drone-ssh to run shell commands on a remote host during a CI workflow, supporting password or key auth, multiple target hosts, and an optional jump host. For teams that still deploy by SSHing into a box and running a script rather than through a proper deployment pipeline.

Multi-host and proxy/jump-host support is built in, so fan-out deploys or bastion-gated hosts don't need extra tooling bolted on. capture_stdout wiring lets you pipe the remote command's output into later workflow steps instead of scraping logs. It's mature (6.2k stars, active CI including a Trivy scan on the action itself) and the README actually documents the ssh-rsa/CASignatureAlgorithms gotcha on newer Ubuntu images that otherwise wastes an afternoon.

Host fingerprint verification is opt-in via the `fingerprint` input, not the default — skip it and you're trusting host key checking to behave correctly on a disposable runner with no persistent known_hosts, which is a real MITM exposure most users won't think to close. `script` is a flat multi-line string handed to a remote shell with no script_stop equivalent built in; forget to prepend `set -e` yourself and a failing first command won't stop the second from running. Credential handling is entirely on the user — password and raw private key both pass through as plain GitHub Secrets inputs, so a misconfigured workflow (fork PR trigger, accidental log echo) can leak SSH credentials directly. There's no retry/backoff beyond a flat timeout, so a transient network blip to the target host just fails the job outright.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →