Since we're working with multiple private repos, and each of them need new private deploy keys, just use the existing ssh-agent running on the server (that should have the keys readily added manually) instead of dealing with keys using secrets ourselves.