GitHub Actions中Docker使用GCP身份联合认证失败求助
问题:GitHub Actions工作负载身份联合认证在Docker中调用GCP SDK超时,服务账号密钥则正常
本地通过挂载application_default_credentials.json文件,Docker内的GCP Python SDK可正常完成认证;但在GitHub Actions中使用工作负载身份联合认证时,出现ReadTimeoutError无法正常运行,而直接传入服务账号密钥JSON作为GitHub Secret则能正常工作。
相关配置
1. GitHub Actions工作流文件
integration-tests: runs-on: uhg-runner permissions: contents: "read" id-token: "write" pull-requests: "write" env: USER: "nonprod" steps: - name: checkout repo code uses: actions/checkout@v3 - name: "Authenticate to Google Cloud" id: "auth" uses: "google-github-actions/auth@v2" with: workload_identity_provider: "xxxx" service_account: "xxxx" token_format: "access_token" create_credentials_file: true - name: Set up Cloud SDK uses: "google-github-actions/setup-gcloud@v2" - name: 'Use gcloud CLI' run: | gcloud info - name: test run: docker compose run --rm api coverage run --source=./src -m pytest tests/integration
2. Docker Compose配置
卷挂载配置
volumes: - $GOOGLE_APPLICATION_CREDENTIALS:/tmp/keys/gcp.json
环境变量配置
- GOOGLE_APPLICATION_CREDENTIALS=/tmp/keys/gcp.json
3. 生成的外部账号凭证文件格式
{"type":"external_account","audience":"//iam.googleapis.com/projects/xxxx/locations/global/workloadIdentityPools/gh-pool/providers/gh-provider", "subject_token_type":"urn:ietf:params:oauth:token-type:jwt", "token_url":"https://sts.googleapis.com/v1/token", "credential_source":{"url":"https://pipelinesghubeus24.actions.githubusercontent.com/xxxx..../idtoken?api-version=2.0&audience=https%3A%2F%2Fiam.googleapis.com%2Fprojects%2F140501271167%2Flocations%2Fglobal%2FworkloadIdentityPools%2Fgh-pool%2Fproviders%2Fgh-provider","headers": {"Authorization":"***"},"format":{"type":"json", "subject_token_field_name":"value"}}, "service_account_impersonation_url":"https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/xxxxxx...us.iam.gserviceaccount.com:generateAccessToken"}
报错信息
运行BigQuery集成测试时触发的超时错误:
self = <urllib3.connectionpool.HTTPSConnectionPool object at 0x7f114160c7a0> method = 'GET' url = '/xxxx/00000000-0000-0000-0000-000000000000/_apis/distributedtask/hubs/A...gleapis.com%2Fprojects%2F140501271167%2Flocations%2Fglobal%2FworkloadIdentityPools%2Fgh-pool%2Fproviders%2Fgh-provider' body = None headers = {'User-Agent': 'python-requests/2.31.0', 'Accept-Encoding': 'gzip, deflate', 'Accept': '*/*', 'Connection': 'keep-aliv...xxxx'} retries = Retry(total=2, connect=None, read=None, redirect=None, status=None) redirect = False, assert_same_host = False timeout = Timeout(connect=120, read=120, total=None), pool_timeout = None release_conn = False, chunked = False, body_pos = None, preload_content = False decode_content = False, response_kw = {} parsed_url = Url(scheme=None, auth=None, host=None, port=None, path='/xxx/ojects%2F140501271167%2Flocations%2Fglobal%2FworkloadIdentityPools%2Fgh-pool%2Fproviders%2Fgh-provider', fragment=None) destination_scheme = None, conn = None, release_this_conn = True http_tunnel_required = False err = ReadTimeoutError("HTTPSConnectionPool(host='pipelinesghubeus24.actions.githubusercontent.com', port=443): Read timed out. (read timeout=120)") clean_exit = False
问题
请问该问题的原因是什么?如何进一步调试排查?
内容的提问来源于stack exchange,提问作者OneTwo
相关产品推荐
相关产品推荐

