如何配置GitHub实现跨仓库PR依赖审批并阻止合并按钮?
解决方案配置步骤
一、自动生成中心API仓库的PR
借助GitHub Actions,在微服务仓库的PR触发时,自动提取更新后的OpenAPI规范并推送到中心API仓库创建关联PR:
- 微服务仓库配置工作流
在微服务仓库的.github/workflows目录下创建auto-create-api-spec-pr.yml,内容如下:
name: Auto Create API Spec PR on: pull_request: types: [opened, synchronize] paths: - 'path/to/your/openapi-spec.yaml' # 替换为微服务内OpenAPI规范的实际路径 jobs: create-api-pr: runs-on: ubuntu-latest steps: - name: 拉取微服务代码 uses: actions/checkout@v4 with: fetch-depth: 0 - name: 拉取中心API仓库代码 uses: actions/checkout@v4 with: repository: your-org/central-api-repo # 替换为中心API仓库的完整地址 token: ${{ secrets.CENTRAL_API_REPO_TOKEN }} # 提前在GitHub Secrets配置有中心仓库读写权限的Token path: central-api - name: 复制更新后的OpenAPI规范 run: | cp path/to/your/openapi-spec.yaml central-api/specs/${{ github.event.pull_request.head.repo.name }}.yaml # 替换为中心仓库中对应微服务规范的存储路径 - name: 在中心API仓库创建PR uses: peter-evans/create-pull-request@v5 with: path: central-api token: ${{ secrets.CENTRAL_API_REPO_TOKEN }} commit-message: "更新${{ github.event.pull_request.head.repo.name }}的API规范 - 关联微服务PR #${{ github.event.pull_request.number }}" title: "[${{ github.event.pull_request.head.repo.name }}] 更新API规范(关联PR #${{ github.event.pull_request.number }})" body: | 此PR更新${{ github.event.pull_request.head.repo.name }}的API规范,关联微服务PR:${{ github.event.pull_request.html_url }} branch: "update-spec-${{ github.event.pull_request.head.repo.name }}-${{ github.event.pull_request.number }}"
- 注意:需在微服务仓库的GitHub Secrets中添加
CENTRAL_API_REPO_TOKEN,该Token需具备中心API仓库的读写权限。
二、跨仓库PR依赖审批,阻止合并按钮
要实现依赖PR获批前阻止目标PR合并,需结合分支保护规则和自定义状态检查:
1. 中心API仓库配置状态检查触发器
当中心API仓库的PR获得两次审批后,向关联的微服务PR发送成功状态检查:
在中心API仓库的.github/workflows目录下创建notify-micro-service-pr.yml:
name: 微服务PR审批通知 on: pull_request_review: types: [submitted] jobs: 检查审批并通知: runs-on: ubuntu-latest if: | github.event.review.state == 'approved' && github.event.pull_request.approvals >= 2 # 检查是否达到两次有效审批 steps: - name: 提取关联微服务PR信息 id: extract-pr run: | PR_BODY="${{ github.event.pull_request.body }}" MICRO_SERVICE_PR_URL=$(echo "$PR_BODY" | grep -o 'https://github.com/[^ ]*') MICRO_SERVICE_REPO=$(echo "$MICRO_SERVICE_PR_URL" | cut -d'/' -f4-5) MICRO_SERVICE_PR_NUMBER=$(echo "$MICRO_SERVICE_PR_URL" | cut -d'/' -f7) echo "repo=$MICRO_SERVICE_REPO" >> $GITHUB_OUTPUT echo "pr-number=$MICRO_SERVICE_PR_NUMBER" >> $GITHUB_OUTPUT - name: 向微服务PR发送成功状态检查 uses: actions/github-script@v7 with: github-token: ${{ secrets.MICRO_SERVICE_REPO_TOKEN }} # 配置有微服务仓库状态检查权限的Token script: | const repoParts = '${{ steps.extract-pr.outputs.repo }}'.split('/'); await github.rest.repos.createCommitStatus({ owner: repoParts[0], repo: repoParts[1], sha: await (async () => { const pr = await github.rest.pulls.get({ owner: repoParts[0], repo: repoParts[1], pull_number: ${{ steps.extract-pr.outputs.pr-number }} }); return pr.data.head.sha; })(), state: 'success', context: 'central-api-spec-approved', description: '中心API规范PR已完成两次审批' });
- 注意:需在中心API仓库的GitHub Secrets中添加
MICRO_SERVICE_REPO_TOKEN,该Token需具备向微服务仓库提交状态检查的权限。
2. 微服务仓库配置分支保护规则
- 进入微服务仓库的
Settings->Branches->Branch protection rules - 选择需要保护的分支(如
main) - 勾选Require status checks to pass before merging
- 在Status checks that are required中添加自定义状态检查项
central-api-spec-approved - 保留原有规则(如Require pull request reviews before merging)
3. (可选)反向依赖配置
若需要中心API仓库的PR依赖微服务PR的审批,只需反向执行上述流程:微服务PR获批后向中心API PR发送状态检查,再在中心API仓库的分支保护规则中添加对应状态检查项。
三、关键注意事项
- Token权限:确保配置的GitHub个人访问令牌(PAT)拥有仓库读写、状态检查提交、PR创建的权限。
- PR关联准确性:第一步创建中心API PR时,需在标题或正文明确关联微服务PR的信息,确保第二步能准确解析出对应PR的地址和编号。
- 审批计数校验:若需要排除PR提交者自身的审批,可通过GitHub API拉取审批列表,过滤后确认有效审批数是否达到2次。
内容的提问来源于stack exchange,提问作者Weso
相关产品推荐
相关产品推荐

