在可重用Workflow的with上下文使用secrets上下文报错,是否不支持?
可重用Workflow的
with上下文是否支持secrets上下文? 结论:不支持。GitHub Actions 规定,调用可重用Workflow时,with 参数的表达式里不能直接引用 secrets 上下文,这就是你遇到报错的根本原因。
正确的密钥传递方式
要把密钥传给可重用Workflow,得用专门的 secrets 字段(和 with 同级),而不是塞进 with 里。
调用方Workflow修改后:
jobs: test-secrets-passing: uses: MyOrg/MyRepo/.github/workflows/myworkflow.yaml@main with: image_name: some-name image_tag: some-tag build_args: | MY_VAR=${{ vars.MY_VAR }} # 单独用secrets字段传递敏感信息 secrets: MY_SECRET: ${{ secrets.MY_SECRET }}
可重用Workflow(myworkflow.yaml)需要先声明接收的密钥:
on: workflow_call: # 定义接收的输入参数 inputs: image_name: required: true type: string image_tag: required: true type: string build_args: required: false type: string # 声明要接收的密钥 secrets: MY_SECRET: required: true jobs: build: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v4 - name: Build and push Docker image uses: docker/build-push-action@v5 with: context: . push: true tags: ${{ inputs.image_name }}:${{ inputs.image_tag }} build-args: ${{ inputs.build_args }} # 在action里引用可重用Workflow接收到的密钥 secrets: | MY_SECRET=${{ secrets.MY_SECRET }}
为什么要这么做?
GitHub 把 with 用于传递非敏感的公开参数,而 secrets 字段是专门为敏感信息设计的,能确保密钥不会被意外暴露在Workflow日志、参数预览等场景中,符合安全规范。
内容的提问来源于stack exchange,提问作者pkaramol
相关产品推荐
相关产品推荐

