You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions拉取私有服务容器时Docker认证失败求助

GitHub Actions Services 拉取GHCR镜像登录失败问题解决

问题场景

搭建CI/CD流水线时,第一步构建Docker镜像并上传至GHCR(GitHub容器注册表)完全正常,但在第二步使用GitHub Actions内置的services功能拉取该镜像作为服务容器时,出现以下登录失败错误:

/usr/bin/docker --config /home/runner/work/_temp/.docker_89dc3924-6afb-4e25-befa-165b2a39812b login -u DanielArmyrConversy --password-stdin
Error: Docker login for '' failed with exit code 1

对应的GitHub Actions脚本如下:

name: Test

env:
  IMAGE_NAME_GH: 'ghcr.io/conversy-ai/conversy-web-client:commit-${{github.sha}}'

jobs:  
  docker-build:
    name: "Docker build"
    runs-on: ubuntu-latest
    steps:
      - name: Checkout
        uses: actions/checkout@v3
        with:
          fetch-depth: 0
      - name: "Build the docker"
        run: |          
          docker build . -t ${IMAGE_NAME_GH}
      - name: "Upload to Github"
        run: |           
          echo '${{secrets.GH_REGISTRY_KEY}}' | docker login  -u ${{ github.actor }} --password-stdin https://ghcr.io                     
          docker push ${IMAGE_NAME_GH}

  service-test:
    name: "Service Test"
    needs: [docker-build]
    runs-on: ubuntu-latest
    services:
      frontend:
        image: ${IMAGE_NAME_GH}
        ports:
          - 3000:3000
        credentials:
          username: ${{ github.actor }}
          password: ${{ secrets.GH_REGISTRY_KEY }}
    steps:
      - name: "APT test"
        run: |
          # Run some scripts that test the APIs

问题原因

GitHub Actions的services.credentials字段默认适配Docker Hub,当拉取GHCR这类第三方私有仓库镜像时,必须明确指定登录的仓库地址。如果缺少registry参数,Actions会尝试登录空地址,从而触发上述错误。

解决方案

在service-test作业的services配置中添加registry: ghcr.io,明确指定登录的仓库地址:

service-test:
    name: "Service Test"
    needs: [docker-build]
    runs-on: ubuntu-latest
    services:
      frontend:
        image: ${IMAGE_NAME_GH}
        ports:
          - 3000:3000
        credentials:
          registry: ghcr.io  # 新增该行,指定登录的仓库地址
          username: ${{ github.actor }}
          password: ${{ secrets.GH_REGISTRY_KEY }}
    steps:
      - name: "APT test"
        run: |
          # Run some scripts that test the APIs

添加该参数后,GitHub Actions会生成正确的登录命令(指定登录到ghcr.io),即可正常拉取私有镜像。

额外检查点

  • 确保secrets.GH_REGISTRY_KEY是拥有GHCR拉取权限的个人访问令牌(PAT),需勾选read:packages权限
  • 确认github.actor对应的账号有权限访问目标GHCR镜像

内容的提问来源于stack exchange,提问作者Daniel Armyr -Conversy-

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 05:07:58