如何在GitHub Actions中配置Poetry用HTTPS访问GHE依赖?
解决方案
1. 创建具备足够权限的GHE个人访问令牌(PAT)
- 在GHE个人设置中生成PAT,勾选repo权限(访问私有仓库的核心权限),若涉及多组织,确保PAT覆盖所有目标组织/仓库的访问范围(可选组织级权限或逐个添加仓库)。
- 将生成的PAT存入当前仓库的GitHub Actions Secrets,命名为
GHE_PAT。
2. 切换依赖链接为HTTPS格式
修改pyproject.toml,把所有GHE仓库的SSH依赖替换为HTTPS:
# 原SSH格式示例 # tool.poetry.dependencies = { internal-pkg = { git = "ssh://git@github.example.com/org/internal-pkg.git", branch = "main" } } # 修改后的HTTPS格式 [tool.poetry.dependencies] internal-pkg = { git = "https://github.example.com/org/internal-pkg.git", branch = "main" }
同时确保所有嵌套依赖(其他GHE仓库的.toml文件)中的GHE依赖也使用HTTPS链接,否则仍会出现凭证缺失问题。
3. 在GitHub Actions工作流中配置Poetry凭证
在工作流文件(如.github/workflows/build.yml)中添加Poetry凭证配置步骤,让Poetry通过HTTPS访问GHE仓库:
jobs: build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 # 安装Python和Poetry - uses: actions/setup-python@v5 with: python-version: "3.11" - run: curl -sSL https://install.python-poetry.org | python3 - # 配置Poetry的GHE访问凭证 - name: Set up Poetry for GHE run: | # 替换github-example为你的GHE域名标识(如ghe-company-com,对应ghe.company.com) poetry config http-basic.github-example your-ghe-username ${{ secrets.GHE_PAT }} # 可选:指定GHE私有包源,确保Poetry识别仓库地址 poetry config repositories.github-example https://github.example.com/api/v3/repos # 执行依赖安装/更新 - run: poetry install --no-root
注意:
http-basic后的标识需与GHE域名对应,用户名可填任意非空值(GHE的PAT验证不强制匹配用户名,填写你的GHE账号名即可)。
4. 处理嵌套依赖的凭证继承
若嵌套依赖的.toml已使用HTTPS链接,上述Poetry配置会自动复用凭证访问对应GHE仓库,无需额外操作。如果上游依赖无法修改为HTTPS,可临时配置Git凭证助手:
- name: Configure Git credential helper run: | git config --global credential.helper store echo "https://your-ghe-username:${{ secrets.GHE_PAT }}@github.example.com" > ~/.git-credentials
这会让Git拉取HTTPS格式的仓库依赖时自动使用凭证,间接解决Poetry的嵌套依赖访问问题。
内容的提问来源于stack exchange,提问作者user24699596
相关产品推荐
相关产品推荐

