GitHub Actions中Terraform对接GCP认证失败求助
GitHub Actions + Terraform 连接GCP认证失败排查
我在使用GitHub Actions结合Terraform做基础设施即代码(IaC)的CI/CD流程时,GCP认证一直失败,以下是详细情况:
第一种测试版本配置与报错
common-terraform.yml 配置
name: 'Common Terraform Workflow' on: workflow_call: jobs: terraform: name: 'Terraform' runs-on: ubuntu-latest defaults: run: shell: bash working-directory: ./terraform steps: - name: Checkout uses: actions/checkout@v4 - name: Setup Terraform uses: hashicorp/setup-terraform@v1 - name: Setup terraform variables id: vars run: |- cat > pipeline.auto.tfvars <<EOF project_id="${{ vars.PROJECT_ID }}" EOF - name: Terraform Init run: terraform init env: GOOGLE_CREDENTIALS: ${{ secrets.TF_GOOGLE_CREDENTIALS }} - name: Terraform Format run: terraform fmt -check env: TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas - name: Terraform Plan run: terraform plan env: TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas - name: Terraform Apply run: terraform apply -auto-approve env: TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas
terraform-dev.yml 配置(两个版本一致)
name: 'Terraform Dev' on: push: branches: - '**' - '!main' pull_request: branches: - '**' - '!main' jobs: call-common-terraform: uses: ./.github/workflows/common-terraform.yml
报错信息
Run terraform init terraform init shell: /usr/bin/bash --noprofile --norc -e -o pipefail {0} env: TERRAFORM_CLI_PATH: /home/runner/work/_temp/7325049d-c6a7-480a-9c4f-2c34d758baec GOOGLE_CREDENTIALS: /home/runner/work/_temp/7325049d-c6a7-480a-9c4f-2c34d758baec/terraform-bin init Initializing the backend... Initializing modules... - pubsub-bq in modules/020-pubsub Downloading registry.terraform.io/terraform-google-modules/pubsub/google 7.0.0 for pubsub-bq.pubsub-bq... - pubsub-bq.pubsub-bq in .terraform/modules/pubsub-bq.pubsub-bq - service-account in modules/010-sa ╷ │ Error: storage.NewClient() failed: dialing: google: could not find default credentials. See https://cloud.google.com/docs/authentication/external/set-up-adc for more information │ │ ╵ Warning: The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/ Warning: The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/ Warning: The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/ Error: Terraform exited with code 1. Error: Process completed with exit code 1.
第二种测试版本配置与报错
common-terraform.yml 配置
name: 'Common Terraform Workflow' on: workflow_call: jobs: terraform: name: 'Terraform' runs-on: ubuntu-latest defaults: run: shell: bash working-directory: ./terraform steps: - name: Checkout uses: actions/checkout@v4 - name: GCP Auth uses: 'google-github-actions/auth@v2' with: credentials_json: '${{ secrets.TF_GOOGLE_CREDENTIALS }}' - name: Setup Terraform uses: hashicorp/setup-terraform@v1 - name: Setup terraform variables id: vars run: |- cat > pipeline.auto.tfvars <<EOF project_id="${{ vars.PROJECT_ID }}" EOF - name: Terraform Init run: terraform init - name: Terraform Format run: terraform fmt -check env: TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas - name: Terraform Plan run: terraform plan env: TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas - name: Terraform Apply run: terraform apply -auto-approve env: TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas
报错信息
Run google-github-actions/auth@v2 with: create_credentials_file: true export_environment_variables: true universe: googleapis.com cleanup_credentials: true access_token_lifetime: 3600s access_token_scopes: https://www.googleapis.com/auth/cloud-platform id_token_include_email: false Error: google-github-actions/auth failed with: the GitHub Action workflow must specify exactly one of "workload_identity_provider" or "credentials_json"! If you are specifying input values via GitHub secrets, ensure the secret is being injected into the environment. By default, secrets are not passed to workflows triggered from forks, including Dependabot.
补充信息
我在GitHub Secrets里配置的TF_GOOGLE_CREDENTIALS是无空格换行的单行格式,内容如下:
{"type": "service_account","project_id": "xyz","private_key_id": "xyz","private_key": "-----BEGIN PRIVATE KEY----- xyz -----END PRIVATE KEY----- ","client_email": "test-sa@xyz.iam.gserviceaccount.com","client_id": "123","auth_uri": "https://accounts.google.com/o/oauth2/auth","token_uri": "https://oauth2.googleapis.com/token","auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs","client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/test-sa%40xyz.iam.gserviceaccount.com","universe_domain": "googleapis.com"}
问题
请问可能是什么原因导致认证失败?
排查方向与解决方案
1. Secrets未正确注入或不存在
从报错能看到两种版本的核心问题都是GitHub Secrets没有被正确加载到工作流中:
- 检查仓库Secrets:确认
TF_GOOGLE_CREDENTIALS确实存在于当前仓库的Settings > Secrets and variables > Actions中,若用组织级Secrets,需确认已授权给当前仓库使用。 - 检查触发场景:如果测试用的是来自fork的PR,GitHub默认不会传递Secrets到工作流,符合你报错里提示的"secrets are not passed to workflows triggered from forks"。
- 检查名称拼写:确认
TF_GOOGLE_CREDENTIALS和工作流里引用的名称完全一致,GitHub Secrets名称大小写敏感。
2. Service Account密钥格式错误
你提到密钥是单行格式,但要注意:
- 私钥部分的换行必须用
\n保留,不能直接删除。比如原始私钥里的换行要替换成\n,正确格式应为:"private_key": "-----BEGIN PRIVATE KEY-----\nabcdefg...\n-----END PRIVATE KEY-----"
如果直接删掉换行,密钥会失效,导致认证失败。
3. 工作流调用的权限问题
因为使用了workflow_call,需确认调用方工作流的权限:
- 若调用方是fork的PR,权限会受限,Secrets无法传递;
- 可在调用时显式指定基础权限,修改
terraform-dev.yml:jobs: call-common-terraform: uses: ./.github/workflows/common-terraform.yml permissions: contents: read id-token: write
4. 临时调试方案
在工作流中添加调试步骤(仅测试用,不要提交到正式分支),确认Secrets是否加载:
- name: Debug Secrets run: echo "GOOGLE_CREDENTIALS exists: ${{ secrets.TF_GOOGLE_CREDENTIALS != '' }}"
内容的提问来源于stack exchange,提问作者kamil1992
相关产品推荐
相关产品推荐

