You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions构建Docker镜像时Secret传递失败的排查求助

GitHub Actions构建Docker镜像时Secret传递失败问题

在GitHub Actions构建Docker镜像过程中,遇到Secret无法正常传递的问题:即使将包含Secret的变量设为环境变量,构建阶段也无法正确使用该Secret。Dockerfile在构建阶段需要访问敏感信息,已在GitHub仓库配置好所需Secret,但构建上下文无法正常访问。

已尝试的操作(针对PARCOURS_SECRET变量)

  • 配置Secret:已在GitHub仓库「Secrets」中添加目标Secret。
  • 使用环境变量传递:尝试在GitHub Actions工作流中将Secret作为环境变量传递。

第一种尝试:通过build-args传递Secret

工作流片段:

name: Build and Push Docker Image
    uses: docker/build-push-action@v6.9.0 
    with:
      context: .  # Use the current directory as the build context
      file: parent/composant-business/document-service/Dockerfile  # Specify the Dockerfile to use
      tags: ghcr.io/${{ github.actor }}/parcoursback-documents:${{ steps.get_version.outputs.version }}  # Tag for the built image
      load: true  # Load the image into the Docker daemon (for local use)
      cache-from: type=gha  # Use GitHub Actions cache as a cache source
      cache-to: type=gha,mode=max  # Store cache in GitHub Actions for future builds
      push: true  # Set to true if you want to push to a remote registry
      build-args: |
        PARCOURS_PACKAGES_URL=${{ secrets.PARCOURS_PACKAGES_URL }}
        PARCOURS_MICROSERVICE_VERSION=${{ steps.get_version.outputs.version }}
        PARCOURS_com_group_artifact=${{ vars.PARCOURS_COM_GROUP_ARTIFACT_DOCUMENT }}
        PARCOURS_SECRET=${{ secrets.PARCOURS_TOKEN }}

对应的Dockerfile片段:

ARG PARCOURS_SECRET

RUN echo "Taking from : ${PARCOURS_PACKAGES_URL}/${PARCOURS_COM_GROUP_ARTIFACT}/${PARCOURS_MICROSERVICE_VERSION}/exemplaire-service-${PARCOURS_MICROSERVICE_VERSION}-develop.jar"

RUN curl -v -L -o exemplaire-service.jar \
      -H "Authorization: Bearer ${PARCOURS_SECRET}" \
      "${PARCOURS_PACKAGES_URL}/${PARCOURS_COM_GROUP_ARTIFACT}/${PARCOURS_MICROSERVICE_VERSION}/exemplaire-service-${PARCOURS_MICROSERVICE_VERSION}-develop.jar" \
      && ls -lh exemplaire-service.jar

第二种尝试:使用Docker Secret挂载

工作流片段:

name: Build and Push Docker Image
    uses: docker/build-push-action@v6.9.0
    with:
      context: .  # Use the current directory as the build context
      file: parent/composant-business/exemplaire-service/Dockerfile  # Specify the Dockerfile to use
      tags: ghcr.io/${{ github.actor }}/parcoursback-exemplaire:${{ steps.get_version.outputs.version }}  # Tag for the built image
      load: true  # Load the image into the Docker daemon (for local use)
      cache-from: type=gha  # Use GitHub Actions cache as a cache source
      cache-to: type=gha,mode=max  # Store cache in GitHub Actions for future builds
      push: true  # Set to true if you want to push to a remote registry
      build-args: |
        PARCOURS_PACKAGES_URL=${{ secrets.PARCOURS_PACKAGES_URL }}
        PARCOURS_MICROSERVICE_VERSION=${{ steps.get_version.outputs.version }}
        PARCOURS_com_group_artifact=${{ vars.PARCOURS_COM_GROUP_ARTIFACT_EXEMPLAIRE }}
      secrets:
        PARCOURS_SECRET=${{ secrets.PARCOURS_TOKEN }}

对应的Dockerfile片段:

RUN --mount=type=secret,id=PARCOURS_SECRET,dst=/home/pass_token curl -v -L -o exemplaire-service.jar \
      -H "Authorization: Bearer $(cat /home/pass_token)" \
      "${PARCOURS_PACKAGES_URL}/${PARCOURS_COM_GROUP_ARTIFACT}/${PARCOURS_MICROSERVICE_VERSION}/exemplaire-service-${PARCOURS_MICROSERVICE_VERSION}-develop.jar" \
      && ls -lh exemplaire-service.jar

相关curl命令日志

#14 0.079   % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
#14 0.079                                  Dload  Upload   Total   Spent    Left  Speed
#14 0.079 
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0*   Trying 140.82.112.33:443...
#14 0.089 * TCP_NODELAY set
#14 0.095 * Connected to maven.pkg.github.com (140.82.112.33) port 443 (#0)
#14 0.096 * ALPN, offering h2
#14 0.096 * ALPN, offering http/1.1
#14 0.102 * successfully set certificate verify locations:
#14 0.102 *   CAfile: /etc/ssl/certs/ca-certificates.crt
#14 0.102   CApath: /etc/ssl/certs
#14 0.103 } [5 bytes data]
#14 0.103 * TLSv1.3 (OUT), TLS handshake, Client hello (1):
#14 0.103 } [512 bytes data]
#14 0.109 * TLSv1.3 (IN), TLS handshake, Server hello (2):
#14 0.109 { [122 bytes data]
#14 0.109 * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
#14 0.109 { [19 bytes data]
#14 0.114 * TLSv1.3 (IN), TLS handshake, Certificate (11):
#14 0.114 { [4847 bytes data]
#14 0.114 * TLSv1.3 (IN), TLS handshake, CERT verify (15):
#14 0.114 { [520 bytes data]
#14 0.114 * TLSv1.3 (IN), TLS handshake, Finished (20):
#14 0.114 { [36 bytes data]
#14 0.114 * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
#14 0.114 } [1 bytes data]
#14 0.114 * TLSv1.3 (OUT), TLS handshake, Finished (20):
#14 0.114 } [36 bytes data]
#14 0.114 * SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256
#14 0.114 * ALPN, server accepted to use h2
#14 0.114 * Server certificate:
#14 0.114 *  subject: CN=*.pkg.github.com
#14 0.114 *  start date: Apr  8 00:00:00 2024 GMT
#14 0.114 *  expire date: Apr  8 23:59:59 2025 GMT
#14 0.114 *  subjectAltName: host "maven.pkg.github.com" matched cert's "*.pkg.github.com"
#14 0.114 *  issuer: C=GB; ST=Greater Manchester; L=Salford; O=Sectigo Limited; CN=Sectigo RSA Domain Validation Secure Server CA
#14 0.114 *  SSL certificate verify ok.
#14 0.115 * Using HTTP2, server supports multi-use
#14 0.115 * Connection state changed (HTTP/2 confirmed)
#14 0.115 * Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=0
#14 0.115 } [5 bytes data]
#14 0.115 * Using Stream ID: 1 (easy handle 0x55a63a569650)
#14 0.115 } [5 bytes data]
#14 0.115 > GET /kouamdo/parcoursback/cmr/notep/document-service/2.0-0014/document-service-2.0-0014-develop.jar HTTP/2
#14 0.115 > Host: maven.pkg.github.com
#14 0.115 > user-agent: curl/7.68.0
#14 0.115 > accept: */*
#14 0.115 > authorization: ***
#14 0.115 > 
#14 0.120 { [5 bytes data]
#14 0.120 * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
#14 0.120 { [57 bytes data]
#14 0.120 * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
#14 0.120 { [57 bytes data]
#14 0.120 * old SSL session ID is stale, removing
#14 0.120 { [5 bytes data]
#14 0.120 * Connection state changed (MAX_CONCURRENT_STREAMS == 100)!
#14 0.120 } [5 bytes data]
#14 0.149 < HTTP/2 401 
#14 0.149 < access-control-allow-methods: GET, HEAD, OPTIONS
#14 0.149 < access-control-allow-origin: *
#14 0.149 < content-security-policy: default-src 'none';
#14 0.149 < content-type: text/plain; charset=utf-8
#14 0.149 < server: GitHub Registry
#14 0.149 < strict-transport-security: max-age=31536000;
#14 0.149 < x-content-type-options: nosniff
#14 0.149 < x-frame-options: DENY
#14 0.149 < x-xss-protection: 1; mode=block
#14 0.149 < date: Mon, 27 Jan 2025 14:13:23 GMT
#14 0.149 < content-length: 156
#14 0.149 < x-github-request-id: 45C0:2CDC52:212C7B8:263C61F:67979483
#14 0.149 < 
#14 0.149 { [156 bytes data]
#14 0.149 
100   156  100   156    0     0   2228      0 --:--:-- --:--:-- --:--:--  2228
#14 0.149 * Connection #0 to host maven.pkg.github.com left intact
#14 0.154 -rw-r--r-- 1 root root 156 Jan 27 14:13 document-service.jar
#14 DONE 0.2s

gh secret list命令输出

C:\Users\Ledoux\Documents\parcoursback_forked>gh secret list
NAME                         UPDATED
PARCOURS_BD_NAME             about 27 days ago
PARCOURS_BD_URL              about 27 days ago
PARCOURS_DB_PASSWORD         about 27 days ago
PARCOURS_DB_USER             about 27 days ago
PARCOURS_PACKAGES_CONTAINER  about 6 days ago
PARCOURS_PACKAGES_URL        about 28 days ago
PARCOURS_TOKEN               about 26 days ago
PARCOURS_TOKEN1              about 1 month ago
PARCOURS_TOKEN_UPLOAD_REPO   about 6 days ago
SONAR_HOST_URL               about 2 months ago
SONAR_TOKEN                  about 1 month ago

从日志可见,尽管已传递Secret,但JAR文件未成功下载(仅156字节,为错误响应内容)。需要指引排查步骤,确保Docker构建过程中能正确访问Secret。

内容的提问来源于stack exchange,提问作者Esaëe Njongssi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 18:45:54