You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions中Docker使用GCP身份联合认证失败求助

问题:GitHub Actions工作负载身份联合认证在Docker中调用GCP SDK超时,服务账号密钥则正常

本地通过挂载application_default_credentials.json文件,Docker内的GCP Python SDK可正常完成认证;但在GitHub Actions中使用工作负载身份联合认证时,出现ReadTimeoutError无法正常运行,而直接传入服务账号密钥JSON作为GitHub Secret则能正常工作。


相关配置

1. GitHub Actions工作流文件

integration-tests:
  runs-on: uhg-runner
  permissions:
    contents: "read"
    id-token: "write"
    pull-requests: "write"
  env:
    USER: "nonprod"
  steps:
    - name: checkout repo code
      uses: actions/checkout@v3
    - name: "Authenticate to Google Cloud"
      id: "auth"
      uses: "google-github-actions/auth@v2"
      with:
        workload_identity_provider: "xxxx"
        service_account: "xxxx"
        token_format: "access_token"
        create_credentials_file: true
    - name: Set up Cloud SDK
      uses: "google-github-actions/setup-gcloud@v2"
    - name: 'Use gcloud CLI'
      run: |
        gcloud info
    - name: test
      run: docker compose run --rm api coverage run  --source=./src -m pytest tests/integration

2. Docker Compose配置

卷挂载配置

volumes:
  - $GOOGLE_APPLICATION_CREDENTIALS:/tmp/keys/gcp.json

环境变量配置

- GOOGLE_APPLICATION_CREDENTIALS=/tmp/keys/gcp.json

3. 生成的外部账号凭证文件格式

{"type":"external_account","audience":"//iam.googleapis.com/projects/xxxx/locations/global/workloadIdentityPools/gh-pool/providers/gh-provider",
"subject_token_type":"urn:ietf:params:oauth:token-type:jwt",
"token_url":"https://sts.googleapis.com/v1/token",
"credential_source":{"url":"https://pipelinesghubeus24.actions.githubusercontent.com/xxxx..../idtoken?api-version=2.0&audience=https%3A%2F%2Fiam.googleapis.com%2Fprojects%2F140501271167%2Flocations%2Fglobal%2FworkloadIdentityPools%2Fgh-pool%2Fproviders%2Fgh-provider","headers":
{"Authorization":"***"},"format":{"type":"json",
"subject_token_field_name":"value"}},
"service_account_impersonation_url":"https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/xxxxxx...us.iam.gserviceaccount.com:generateAccessToken"}

报错信息

运行BigQuery集成测试时触发的超时错误:

self = <urllib3.connectionpool.HTTPSConnectionPool object at 0x7f114160c7a0>
method = 'GET'
url = '/xxxx/00000000-0000-0000-0000-000000000000/_apis/distributedtask/hubs/A...gleapis.com%2Fprojects%2F140501271167%2Flocations%2Fglobal%2FworkloadIdentityPools%2Fgh-pool%2Fproviders%2Fgh-provider'
body = None
headers = {'User-Agent': 'python-requests/2.31.0', 'Accept-Encoding': 'gzip, deflate', 'Accept': '*/*', 'Connection': 'keep-aliv...xxxx'}
retries = Retry(total=2, connect=None, read=None, redirect=None, status=None)
redirect = False, assert_same_host = False
timeout = Timeout(connect=120, read=120, total=None), pool_timeout = None
release_conn = False, chunked = False, body_pos = None, preload_content = False
decode_content = False, response_kw = {}
parsed_url = Url(scheme=None, auth=None, host=None, port=None, path='/xxx/ojects%2F140501271167%2Flocations%2Fglobal%2FworkloadIdentityPools%2Fgh-pool%2Fproviders%2Fgh-provider', fragment=None)
destination_scheme = None, conn = None, release_this_conn = True
http_tunnel_required = False
err = ReadTimeoutError("HTTPSConnectionPool(host='pipelinesghubeus24.actions.githubusercontent.com', port=443): Read timed out. (read timeout=120)")
clean_exit = False

问题

请问该问题的原因是什么?如何进一步调试排查?

内容的提问来源于stack exchange,提问作者OneTwo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 19:45:28