You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Cloudflare白名单GitHub IP,恢复GitHub Actions FTP部署

解决GitHub Actions FTP部署被Cloudflare拦截的问题

之前用GitHub Actions通过FTP更新服务器一直正常,集成Cloudflare后,为了安全设置了仅允许本国流量访问,结果GitHub Actions的部署任务直接失败了。已经确定是Cloudflare的配置导致的问题,但不知道怎么把GitHub的IP加进白名单恢复正常。用的是SamKirkland/FTP-Deploy-Action这个Action,报错信息如下:

Run SamKirkland/FTP-Deploy-Action@v4.3.4
----------------------------------------------------------------
🚀 Thanks for using ftp-deploy. Let's deploy some stuff!   
----------------------------------------------------------------
If you found this project helpful, please support it
by giving it a ⭐ on Github --> https://github.com/SamKirkland/FTP-Deploy-Action
or add a badge 🏷️ to your projects readme --> https://github.com/SamKirkland/FTP-Deploy-Action#badge
Failed to connect, are you sure your server works via FTP or FTPS? Users sometimes get this error when the server only supports SFTP.

----------------------------------------------------------------
--------------  🔥🔥🔥 an error occurred  🔥🔥🔥  --------------
----------------------------------------------------------------

----------------------------------------------------------------
----------------------  full error below  ----------------------
----------------------------------------------------------------

Error: Timeout (control socket)
    at Socket.<anonymous> (/home/runner/work/_actions/SamKirkland/FTP-Deploy-Action/v4.3.4/dist/index.js:5288:33)
    at Object.onceWrapper (node:events:627:28)
    at Socket.emit (node:events:513:28)
    at Socket._onTimeout (node:net:550:8)
    at listOnTimeout (node:internal/timers:559:17)
    at processTimers (node:internal/timers:502:7)
Error: Error: Timeout (control socket)

解决步骤

1. 获取GitHub Actions的IP段

GitHub官方会定期更新Actions运行所使用的IP地址范围,你可以直接获取官方公布的完整IP段列表。如果嫌麻烦,也可以在GitHub Actions的部署脚本里先执行命令curl ifconfig.me获取当前runner的公网IP,不过这种动态方式每次部署都要获取,不如直接加官方IP段稳妥。

2. 在Cloudflare中添加IP白名单规则

  • 登录Cloudflare控制台,进入你的域名管理页面
  • 找到「安全」菜单下的「WAF」,再进入「工具」里的「IP访问规则」
  • 点击「创建规则」,动作选择「允许」
  • 在「IP地址」字段填入你拿到的GitHub Actions IP段,规则名称可以设为「允许GitHub Actions部署访问」
  • 保存规则,等待生效

3. 额外注意事项

如果你的FTP用的是被动模式,要确保Cloudflare没有拦截FTP的被动端口范围,或者把FTP改成主动模式。另外,Cloudflare默认对FTP的支持有限,要是还不行,可以检查服务器的FTP配置,确保端口(默认21)在Cloudflare的允许范围内。

内容的提问来源于stack exchange,提问作者Austin Sanga

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 16:15:26