GitHub私有运行器接入Azure VNET后无法访问互联网的问题排查
问题:Azure VNET内GitHub私有托管运行器无法下载依赖(yarn/npm超时)
我将数据库、存储容器等资源部署在Azure VNET后方,为了让GitHub Actions能够完成部署并访问这些资源以执行构建步骤,按照官方教程配置了集成Azure的GitHub私有托管运行器。但使用该运行器执行GitHub Actions时,出现node_modules无法下载的问题;切换为yarn后,出现网络超时错误,错误信息如下:
Run yarn install yarn install v1.22.22 [1/4] Resolving packages... [2/4] Fetching packages... info There appears to be trouble with your network connection. Retrying... info There appears to be trouble with your network connection. Retrying... info There appears to be trouble with your network connection. Retrying... info There appears to be trouble with your network connection. Retrying... error AggregateError [ETIMEDOUT]: at internalConnectMultiple (node:net:1118:18) info Visit https://yarnpkg.com/en/docs/cli/install for documentation about this command. at internalConnectMultiple (node:net:1186:5) at Timeout.internalConnectMultipleTimeout (node:net:1712:5) at listOnTimeout (node:internal/timers:583:11) at process.processTimers (node:internal/timers:519:7) Error: Process completed with exit code 1.
解决方法
- 核心问题确实是VNET内的运行器缺少出站互联网访问权限,yarn、npm需要访问外部包源拉取依赖,必须配置对应的访问权限。
- 调整网络安全组(NSG)出站规则:找到运行器所在子网关联的NSG,添加入站?不,出站规则——允许该子网的出站流量访问HTTPS(443端口),因为包管理器均通过HTTPS协议拉取依赖。如果需要更严格的管控,可以只允许访问特定包源域名(如registry.npmjs.org、yarnpkg.com等)的443端口出站流量。
- 配置VNET的互联网出口:如果VNET本身没有互联网访问能力,需要为运行器所在的虚拟机/虚拟机规模集配置NAT网关或关联公共IP,确保运行器能通过公网访问外部资源。
- 检查.bicep文件中的NSG配置:官方教程的.bicep可能默认限制了出站流量,需要修改对应NSG的出站规则部分,确保上述HTTPS出站权限已开放。
内容的提问来源于stack exchange,提问作者Qiuzman
相关产品推荐
相关产品推荐

