You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

托管身份联合凭据策略中allowedRepoOwners应如何配置?

关于GitHub工作负载身份联合与Azure策略配置的疑问

我已配置好工作负载身份联合,配置代码大致如下:

var applicationRegistrationDisplayName = 'GitHub Actions Application Deployer.'
var githubOIDCProvider = 'https://token.actions.githubusercontent.com'
var microsoftEntraAudience = 'api://AzureADTokenExchange'
var applicationRegistrationName = 'app-deployer'
resource GithubActionsApplication 'Microsoft.Graph/applications@v1.0' = {
  uniqueName: applicationRegistrationName
  displayName: applicationRegistrationDisplayName

  resource githubFederatedIdentityCredential 'federatedIdentityCredentials@v1.0' = {
    name: '${GithubActionsApplication.uniqueName}/githubFederatedIdentityCredential'
    audiences: [microsoftEntraAudience]
    description: 'Identity for application to deploy the root infrastructure.'
    issuer: githubOIDCProvider
    subject: GitHubActionsFederatedIdentitySubject
    }
}

resource githubActionsServicePrincipal 'Microsoft.Graph/servicePrincipals@v1.0' = {
    displayName: applicationRegistrationDisplayName
    appId: GithubActionsApplication.appId
}

随后我添加了Azure内置策略定义:来自GitHub的托管身份联合凭据应来自受信任的存储库所有者,希望以此限制所有尝试连接的联合身份的允许存储库范围。但我不确定应在allowedRepoOwners数组中填入什么内容,具体疑问如下:

  • 若我拥有类似https://github.com/<organizationX>的组织,应填入https://github.com/<organizationX>还是organizationX?
  • 在管理组级别添加该配置后,是否足以限制此所有者下的所有存储库(如https://github.com/<organizationX>/<RepoA>、https://github.com/<organizationX>/<RepoB>)?

我曾考虑直接测试,但也希望了解如何从策略定义中提取此类信息,同时想改进相关文档,但不知从何处着手。

内容的提问来源于stack exchange,提问作者Veksi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 06:27:45