如何在属性映射与Attribute Conditions中使用GitHub不可变ID?
GitHub Actions绑定Google Cloud身份验证的ID使用问题
从GitHub Actions配置Google Cloud身份验证的安全注意事项中,建议使用GitHub的不可变/唯一ID(所有者|仓库)而非名称进行绑定,这一建议较为合理。
尽管谷歌推荐使用ID,但其文档中仍采用名称示例:
gcloud iam workload-identity-pools providers create-oidc "my-repo" \ --project="${PROJECT_ID}" \ --location="global" \ --workload-identity-pool="github" \ --display-name="My GitHub repo Provider" \ --attribute-mapping="google.subject=assertion.sub,attribute.actor=assertion.actor,attribute.repository=assertion.repository,attribute.repository_owner=assertion.repository_owner" \ --attribute-condition="assertion.repository_owner == '${OWNER}'" \ --issuer-uri="https://token.actions.githubusercontent.com"
我知晓如何修改--attribute-condition以使用ID,但不清楚如何修改--attribute-mapping来纳入ID。直接将--attribute-mapping的值修改为例如attribute.repository_id=assertion.repository_id,以匹配--attribute-condition中的assertion.repository_owner_id=="{OWNER_ID}",这种方式无法生效。
通过GitHub OIDC Debugger可确认,ID声明已包含在令牌中:
{ ... "repository": "{OWNER}/{REPO}", "repository_id": "{REPO_ID}", "repository_owner": "{OWNER}", "repository_owner_id": "{OWNER_ID}", ... }
内容的提问来源于stack exchange,提问作者DazWilkin
相关产品推荐
相关产品推荐

