You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions中Terraform对接GCP认证失败求助

GitHub Actions + Terraform 连接GCP认证失败排查

我在使用GitHub Actions结合Terraform做基础设施即代码(IaC)的CI/CD流程时,GCP认证一直失败,以下是详细情况:


第一种测试版本配置与报错

common-terraform.yml 配置

name: 'Common Terraform Workflow'

on:
  workflow_call:

jobs:
  terraform:
    name: 'Terraform'
    runs-on: ubuntu-latest

    defaults:
      run:
        shell: bash
        working-directory: ./terraform

    steps:
    - name: Checkout
      uses: actions/checkout@v4

    - name: Setup Terraform
      uses: hashicorp/setup-terraform@v1

    - name: Setup terraform variables
      id: vars
      run: |-
        cat > pipeline.auto.tfvars <<EOF
        project_id="${{ vars.PROJECT_ID }}" 
        EOF    

    - name: Terraform Init
      run: terraform init
      env:
        GOOGLE_CREDENTIALS: ${{ secrets.TF_GOOGLE_CREDENTIALS }}

    - name: Terraform Format
      run: terraform fmt -check
      env:
        TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas

    - name: Terraform Plan
      run: terraform plan
      env:
        TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas

    - name: Terraform Apply
      run: terraform apply -auto-approve
      env:
        TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas

terraform-dev.yml 配置(两个版本一致)

name: 'Terraform Dev'

on:
  push:
    branches:
      - '**'
      - '!main'
  pull_request:
    branches:
      - '**'
      - '!main'

jobs:
  call-common-terraform:
    uses: ./.github/workflows/common-terraform.yml

报错信息

Run terraform init
  terraform init
  shell: /usr/bin/bash --noprofile --norc -e -o pipefail {0}
  env:
    TERRAFORM_CLI_PATH: /home/runner/work/_temp/7325049d-c6a7-480a-9c4f-2c34d758baec
    GOOGLE_CREDENTIALS: 
/home/runner/work/_temp/7325049d-c6a7-480a-9c4f-2c34d758baec/terraform-bin init
Initializing the backend...
Initializing modules...
- pubsub-bq in modules/020-pubsub
Downloading registry.terraform.io/terraform-google-modules/pubsub/google 7.0.0 for pubsub-bq.pubsub-bq...
- pubsub-bq.pubsub-bq in .terraform/modules/pubsub-bq.pubsub-bq
- service-account in modules/010-sa
╷
│ Error: storage.NewClient() failed: dialing: google: could not find default credentials. See https://cloud.google.com/docs/authentication/external/set-up-adc for more information
│ 
│ 
╵

Warning: The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/

Warning: The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/

Warning: The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Error: Terraform exited with code 1.
Error: Process completed with exit code 1.

第二种测试版本配置与报错

common-terraform.yml 配置

name: 'Common Terraform Workflow'

on:
  workflow_call:

jobs:
  terraform:
    name: 'Terraform'
    runs-on: ubuntu-latest

    defaults:
      run:
        shell: bash
        working-directory: ./terraform

    steps:
    - name: Checkout
      uses: actions/checkout@v4

    - name: GCP Auth
      uses: 'google-github-actions/auth@v2'
      with:
        credentials_json: '${{ secrets.TF_GOOGLE_CREDENTIALS }}'

    - name: Setup Terraform
      uses: hashicorp/setup-terraform@v1

    - name: Setup terraform variables
      id: vars
      run: |-
        cat > pipeline.auto.tfvars <<EOF
        project_id="${{ vars.PROJECT_ID }}" 
        EOF    

    - name: Terraform Init
      run: terraform init

    - name: Terraform Format
      run: terraform fmt -check
      env:
        TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas

    - name: Terraform Plan
      run: terraform plan
      env:
        TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas

    - name: Terraform Apply
      run: terraform apply -auto-approve
      env:
        TF_VAR_schema_path: $GITHUB_WORKSPACE/terraform/schemas

报错信息

Run google-github-actions/auth@v2
  with:
    create_credentials_file: true
    export_environment_variables: true
    universe: googleapis.com
    cleanup_credentials: true
    access_token_lifetime: 3600s
    access_token_scopes: https://www.googleapis.com/auth/cloud-platform
    id_token_include_email: false
Error: google-github-actions/auth failed with: the GitHub Action workflow must specify exactly one of "workload_identity_provider" or "credentials_json"! If you are specifying input values via GitHub secrets, ensure the secret is being injected into the environment. By default, secrets are not passed to workflows triggered from forks, including Dependabot.

补充信息

我在GitHub Secrets里配置的TF_GOOGLE_CREDENTIALS是无空格换行的单行格式,内容如下:

{"type": "service_account","project_id": "xyz","private_key_id": "xyz","private_key": "-----BEGIN PRIVATE KEY----- xyz -----END PRIVATE KEY----- ","client_email": "test-sa@xyz.iam.gserviceaccount.com","client_id": "123","auth_uri": "https://accounts.google.com/o/oauth2/auth","token_uri": "https://oauth2.googleapis.com/token","auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs","client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/test-sa%40xyz.iam.gserviceaccount.com","universe_domain": "googleapis.com"}

问题

请问可能是什么原因导致认证失败?


排查方向与解决方案

1. Secrets未正确注入或不存在

从报错能看到两种版本的核心问题都是GitHub Secrets没有被正确加载到工作流中:

  • 检查仓库Secrets:确认TF_GOOGLE_CREDENTIALS确实存在于当前仓库的Settings > Secrets and variables > Actions中,若用组织级Secrets,需确认已授权给当前仓库使用。
  • 检查触发场景:如果测试用的是来自fork的PR,GitHub默认不会传递Secrets到工作流,符合你报错里提示的"secrets are not passed to workflows triggered from forks"。
  • 检查名称拼写:确认TF_GOOGLE_CREDENTIALS和工作流里引用的名称完全一致,GitHub Secrets名称大小写敏感。

2. Service Account密钥格式错误

你提到密钥是单行格式,但要注意:

  • 私钥部分的换行必须用\n保留,不能直接删除。比如原始私钥里的换行要替换成\n,正确格式应为:
    "private_key": "-----BEGIN PRIVATE KEY-----\nabcdefg...\n-----END PRIVATE KEY-----"
    如果直接删掉换行,密钥会失效,导致认证失败。

3. 工作流调用的权限问题

因为使用了workflow_call,需确认调用方工作流的权限:

  • 若调用方是fork的PR,权限会受限,Secrets无法传递;
  • 可在调用时显式指定基础权限,修改terraform-dev.yml:
    jobs:
      call-common-terraform:
        uses: ./.github/workflows/common-terraform.yml
        permissions:
          contents: read
          id-token: write
    

4. 临时调试方案

在工作流中添加调试步骤(仅测试用,不要提交到正式分支),确认Secrets是否加载:

- name: Debug Secrets
  run: echo "GOOGLE_CREDENTIALS exists: ${{ secrets.TF_GOOGLE_CREDENTIALS != '' }}"

内容的提问来源于stack exchange,提问作者kamil1992

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 06:07:37