ryanzidago
I use GitHub Actions to run tests every time I commit.
I have an application that uses a private repo on GitHub as a dependency.
My mix.exs file looks like this:
{:private_dependency, git: "git@github.com:ORGANIZATION/private_dependency.git"}, ref: "sha_of_working_commit_on_my_private_dependency_repo"}
However, GitHub Actions fails to fetch this particular dependency:
git@github.com: Permission denied (publickey).
fatal: Could not read from remote repository.
Please make sure you have the correct access rights
and the repository exists.
** (Mix) Command "git --git-dir=.git fetch --force --quiet --progress" failed
##[error]Process completed with exit code 1.
How to fetch a private dependency on GitHub Actions?
Trending in Questions
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
Hello,
I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind.
However, when I launch mix phx.server, I get an error...
New
Hi everyone.
My team and I have been working on a fairly modest app based around video streaming and chat, but we’ve landed a customer t...
New
I really like the adapter patterns that ecto, nebulex, waffle, etc. use and would love find something similar for a key management servic...
New
Hello folks!
So at work, we are seeing some situations where we have to define some “fixed” strings that are used across the codebase in...
New
I’m working on a small exercise involving update_in/3, and I came up with this solution:
data = %{
name: "Periodic Table",
category:...
New
How Can I Optimise Compile Time Dependencies
I have been building an elixir application for about 2 years now. Many modules and files ha...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
A little off-topic, but I feel like people here have a good head on their shoulders.
I used to be quite good at making software. Was luc...
New
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
I fully migrated to my own harness from Anthropic/Gemini and I think it’s time to share it. Welcome DSH, the DeepSeek Harness, fully writ...
New
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
There has been a thread to discuss the Stack Overflow Developer Survey on this forum every year since 2018, so here’s yet another one for...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #ai
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #blog-post
- #elixirconf-us
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #security
- #metaprogramming











Showing Posts 1 to 7- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
NobbZ
Add a private SSH key to the action that has read only access to the private repository.
ryanzidago
How though?
I’ve been looking for how to add an SSH key to GitHub Actions, stumbled onto this blogpost which refers to this action.
ssh-keygen -t ed25519 -a 100 -f /path/to/filesecretconfiguration of each repository on GitHubdeploy_keyconfiguration of the repository where I ran GitHub Actionswebfactory/ssh-agentaction.However, I still get the following error message:
NobbZ
I have no clue how to do this in GHA, but for GitLab CI I usually have the private key as a variable, which I put into an
ssh-agentsession.Roughly:
I’m not sure though how exactly GHA and secrets work, therefore you might need to adjust this to GHA.
The public part of that key has to be added to that private repository. Usually it is added as a read only deploy key.
mpraski
In Github Actions you may want to set the
GITHUB_TOKENvariable in the step where you pull the repos:You will need to generate a token with valid claims for this private repo and include it in your repo’s secrets. Notice how git is being configured to always include your token in the URL (
https://${GITHUB_TOKEN}:x-oauth-basic@github.com) instead of just callinghttps://github.com/. Hopefully this configuration will suffice, but you’ll have to test it out.Read more on the token here: Use GITHUB_TOKEN for authentication in workflows - GitHub Docs.
ryanzidago
I finally got it working.
In my
mix.exsfile, I fetched the private dependency with SSH. Then I updated my workflow definition file with thewebfactory/ssh-agentaction; followed the steps in the README and added a deploy_key to the private dependency that GHA was trying to fetch.More here: What is the proper private key format? · Issue #31 · webfactory/ssh-agent · GitHub
mpraski
Ah nice, good to know there’s more than one way to fetch private repos in GA.
I would probably still opt for the token way, no need to maintain deployment keys in the projects, just the secrets.
Yegair
Thanks for the tip, I had the additional problem, that my build runs mostly inside a Dockerfile, so I had to add an SSH mount as well. Maybe it helps someone:
Then in the GitHub Actions workflow