GitHub Actions构建Docker镜像时Secret传递失败的排查求助
GitHub Actions构建Docker镜像时Secret传递失败问题
在GitHub Actions构建Docker镜像过程中,遇到Secret无法正常传递的问题:即使将包含Secret的变量设为环境变量,构建阶段也无法正确使用该Secret。Dockerfile在构建阶段需要访问敏感信息,已在GitHub仓库配置好所需Secret,但构建上下文无法正常访问。
已尝试的操作(针对PARCOURS_SECRET变量)
- 配置Secret:已在GitHub仓库「Secrets」中添加目标Secret。
- 使用环境变量传递:尝试在GitHub Actions工作流中将Secret作为环境变量传递。
第一种尝试:通过build-args传递Secret
工作流片段:
name: Build and Push Docker Image uses: docker/build-push-action@v6.9.0 with: context: . # Use the current directory as the build context file: parent/composant-business/document-service/Dockerfile # Specify the Dockerfile to use tags: ghcr.io/${{ github.actor }}/parcoursback-documents:${{ steps.get_version.outputs.version }} # Tag for the built image load: true # Load the image into the Docker daemon (for local use) cache-from: type=gha # Use GitHub Actions cache as a cache source cache-to: type=gha,mode=max # Store cache in GitHub Actions for future builds push: true # Set to true if you want to push to a remote registry build-args: | PARCOURS_PACKAGES_URL=${{ secrets.PARCOURS_PACKAGES_URL }} PARCOURS_MICROSERVICE_VERSION=${{ steps.get_version.outputs.version }} PARCOURS_com_group_artifact=${{ vars.PARCOURS_COM_GROUP_ARTIFACT_DOCUMENT }} PARCOURS_SECRET=${{ secrets.PARCOURS_TOKEN }}
对应的Dockerfile片段:
ARG PARCOURS_SECRET RUN echo "Taking from : ${PARCOURS_PACKAGES_URL}/${PARCOURS_COM_GROUP_ARTIFACT}/${PARCOURS_MICROSERVICE_VERSION}/exemplaire-service-${PARCOURS_MICROSERVICE_VERSION}-develop.jar" RUN curl -v -L -o exemplaire-service.jar \ -H "Authorization: Bearer ${PARCOURS_SECRET}" \ "${PARCOURS_PACKAGES_URL}/${PARCOURS_COM_GROUP_ARTIFACT}/${PARCOURS_MICROSERVICE_VERSION}/exemplaire-service-${PARCOURS_MICROSERVICE_VERSION}-develop.jar" \ && ls -lh exemplaire-service.jar
第二种尝试:使用Docker Secret挂载
工作流片段:
name: Build and Push Docker Image uses: docker/build-push-action@v6.9.0 with: context: . # Use the current directory as the build context file: parent/composant-business/exemplaire-service/Dockerfile # Specify the Dockerfile to use tags: ghcr.io/${{ github.actor }}/parcoursback-exemplaire:${{ steps.get_version.outputs.version }} # Tag for the built image load: true # Load the image into the Docker daemon (for local use) cache-from: type=gha # Use GitHub Actions cache as a cache source cache-to: type=gha,mode=max # Store cache in GitHub Actions for future builds push: true # Set to true if you want to push to a remote registry build-args: | PARCOURS_PACKAGES_URL=${{ secrets.PARCOURS_PACKAGES_URL }} PARCOURS_MICROSERVICE_VERSION=${{ steps.get_version.outputs.version }} PARCOURS_com_group_artifact=${{ vars.PARCOURS_COM_GROUP_ARTIFACT_EXEMPLAIRE }} secrets: PARCOURS_SECRET=${{ secrets.PARCOURS_TOKEN }}
对应的Dockerfile片段:
RUN --mount=type=secret,id=PARCOURS_SECRET,dst=/home/pass_token curl -v -L -o exemplaire-service.jar \ -H "Authorization: Bearer $(cat /home/pass_token)" \ "${PARCOURS_PACKAGES_URL}/${PARCOURS_COM_GROUP_ARTIFACT}/${PARCOURS_MICROSERVICE_VERSION}/exemplaire-service-${PARCOURS_MICROSERVICE_VERSION}-develop.jar" \ && ls -lh exemplaire-service.jar
相关curl命令日志
#14 0.079 % Total % Received % Xferd Average Speed Time Time Time Current #14 0.079 Dload Upload Total Spent Left Speed #14 0.079 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0* Trying 140.82.112.33:443... #14 0.089 * TCP_NODELAY set #14 0.095 * Connected to maven.pkg.github.com (140.82.112.33) port 443 (#0) #14 0.096 * ALPN, offering h2 #14 0.096 * ALPN, offering http/1.1 #14 0.102 * successfully set certificate verify locations: #14 0.102 * CAfile: /etc/ssl/certs/ca-certificates.crt #14 0.102 CApath: /etc/ssl/certs #14 0.103 } [5 bytes data] #14 0.103 * TLSv1.3 (OUT), TLS handshake, Client hello (1): #14 0.103 } [512 bytes data] #14 0.109 * TLSv1.3 (IN), TLS handshake, Server hello (2): #14 0.109 { [122 bytes data] #14 0.109 * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): #14 0.109 { [19 bytes data] #14 0.114 * TLSv1.3 (IN), TLS handshake, Certificate (11): #14 0.114 { [4847 bytes data] #14 0.114 * TLSv1.3 (IN), TLS handshake, CERT verify (15): #14 0.114 { [520 bytes data] #14 0.114 * TLSv1.3 (IN), TLS handshake, Finished (20): #14 0.114 { [36 bytes data] #14 0.114 * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): #14 0.114 } [1 bytes data] #14 0.114 * TLSv1.3 (OUT), TLS handshake, Finished (20): #14 0.114 } [36 bytes data] #14 0.114 * SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256 #14 0.114 * ALPN, server accepted to use h2 #14 0.114 * Server certificate: #14 0.114 * subject: CN=*.pkg.github.com #14 0.114 * start date: Apr 8 00:00:00 2024 GMT #14 0.114 * expire date: Apr 8 23:59:59 2025 GMT #14 0.114 * subjectAltName: host "maven.pkg.github.com" matched cert's "*.pkg.github.com" #14 0.114 * issuer: C=GB; ST=Greater Manchester; L=Salford; O=Sectigo Limited; CN=Sectigo RSA Domain Validation Secure Server CA #14 0.114 * SSL certificate verify ok. #14 0.115 * Using HTTP2, server supports multi-use #14 0.115 * Connection state changed (HTTP/2 confirmed) #14 0.115 * Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=0 #14 0.115 } [5 bytes data] #14 0.115 * Using Stream ID: 1 (easy handle 0x55a63a569650) #14 0.115 } [5 bytes data] #14 0.115 > GET /kouamdo/parcoursback/cmr/notep/document-service/2.0-0014/document-service-2.0-0014-develop.jar HTTP/2 #14 0.115 > Host: maven.pkg.github.com #14 0.115 > user-agent: curl/7.68.0 #14 0.115 > accept: */* #14 0.115 > authorization: *** #14 0.115 > #14 0.120 { [5 bytes data] #14 0.120 * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): #14 0.120 { [57 bytes data] #14 0.120 * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): #14 0.120 { [57 bytes data] #14 0.120 * old SSL session ID is stale, removing #14 0.120 { [5 bytes data] #14 0.120 * Connection state changed (MAX_CONCURRENT_STREAMS == 100)! #14 0.120 } [5 bytes data] #14 0.149 < HTTP/2 401 #14 0.149 < access-control-allow-methods: GET, HEAD, OPTIONS #14 0.149 < access-control-allow-origin: * #14 0.149 < content-security-policy: default-src 'none'; #14 0.149 < content-type: text/plain; charset=utf-8 #14 0.149 < server: GitHub Registry #14 0.149 < strict-transport-security: max-age=31536000; #14 0.149 < x-content-type-options: nosniff #14 0.149 < x-frame-options: DENY #14 0.149 < x-xss-protection: 1; mode=block #14 0.149 < date: Mon, 27 Jan 2025 14:13:23 GMT #14 0.149 < content-length: 156 #14 0.149 < x-github-request-id: 45C0:2CDC52:212C7B8:263C61F:67979483 #14 0.149 < #14 0.149 { [156 bytes data] #14 0.149 100 156 100 156 0 0 2228 0 --:--:-- --:--:-- --:--:-- 2228 #14 0.149 * Connection #0 to host maven.pkg.github.com left intact #14 0.154 -rw-r--r-- 1 root root 156 Jan 27 14:13 document-service.jar #14 DONE 0.2s
gh secret list命令输出
C:\Users\Ledoux\Documents\parcoursback_forked>gh secret list NAME UPDATED PARCOURS_BD_NAME about 27 days ago PARCOURS_BD_URL about 27 days ago PARCOURS_DB_PASSWORD about 27 days ago PARCOURS_DB_USER about 27 days ago PARCOURS_PACKAGES_CONTAINER about 6 days ago PARCOURS_PACKAGES_URL about 28 days ago PARCOURS_TOKEN about 26 days ago PARCOURS_TOKEN1 about 1 month ago PARCOURS_TOKEN_UPLOAD_REPO about 6 days ago SONAR_HOST_URL about 2 months ago SONAR_TOKEN about 1 month ago
从日志可见,尽管已传递Secret,但JAR文件未成功下载(仅156字节,为错误响应内容)。需要指引排查步骤,确保Docker构建过程中能正确访问Secret。
内容的提问来源于stack exchange,提问作者Esaëe Njongssi
相关产品推荐
相关产品推荐

