You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在属性映射与Attribute Conditions中使用GitHub不可变ID?

GitHub Actions绑定Google Cloud身份验证的ID使用问题

从GitHub Actions配置Google Cloud身份验证的安全注意事项中,建议使用GitHub的不可变/唯一ID(所有者|仓库)而非名称进行绑定,这一建议较为合理。

尽管谷歌推荐使用ID,但其文档中仍采用名称示例:

gcloud iam workload-identity-pools providers create-oidc "my-repo" \
--project="${PROJECT_ID}" \
--location="global" \
--workload-identity-pool="github" \
--display-name="My GitHub repo Provider" \
--attribute-mapping="google.subject=assertion.sub,attribute.actor=assertion.actor,attribute.repository=assertion.repository,attribute.repository_owner=assertion.repository_owner" \
--attribute-condition="assertion.repository_owner == '${OWNER}'" \
--issuer-uri="https://token.actions.githubusercontent.com"

我知晓如何修改--attribute-condition以使用ID,但不清楚如何修改--attribute-mapping来纳入ID。直接将--attribute-mapping的值修改为例如attribute.repository_id=assertion.repository_id,以匹配--attribute-condition中的assertion.repository_owner_id=="{OWNER_ID}",这种方式无法生效。

通过GitHub OIDC Debugger可确认,ID声明已包含在令牌中:

{
  ...
  "repository": "{OWNER}/{REPO}",
  "repository_id": "{REPO_ID}",
  "repository_owner": "{OWNER}",
  "repository_owner_id": "{OWNER_ID}",
  ...
}

内容的提问来源于stack exchange,提问作者DazWilkin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 05:35:19