You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨仓库调用GitHub可复用工作流时Azure登录失败问题排查

跨仓库调用GitHub Actions可复用工作流Azure登录失败的原因

问题场景

我在GitHub Actions中搭建CI/CD体系,在名为BuildTemplate的仓库中配置了可复用工作流,供其他项目仓库调用。该工作流包含Azure登录及从密钥保管库下载文件的步骤,Azure登录所需的AZURE_CLIENT_ID、AZURE_TENANT_ID、AZURE_SUBSCRIPTION_ID均存储在BuildTemplate仓库的Settings -> Secrets and Variables -> Actions -> Repository Secrets中。

可复用工作流代码

jobs:
  download_secure_file:
    runs-on: [self-hosted, github-my-selfhosted-runner]
    steps:
      - name: Login to Azure
        uses: Azure/login@v1
        with:
          client-id: ${{ secrets.AZURE_CLIENT_ID }}
          tenant-id: ${{ secrets.AZURE_TENANT_ID }}
          subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }}

跨仓库调用代码

jobs:
  download_secure_file:
    name: Download Secure File
    uses: MyOrg/MyReusableRepo/.github/workflows/template-download-secure-file.yml@main

错误信息

Run Azure/login@v1
Error: Az CLI Login failed. Please check the credentials and make sure az is installed on the runner. For more information refer https://aka.ms/create-secrets-for-GitHub-workflows

同仓库调用成功日志

Run Azure/login@v1
Using OIDC authentication...
Federated token details:
issuer - https://token.actions.githubusercontent.com
subject claim - repo:MyOrg/MyRepo:ref:refs/heads/feature/MyFeature-7596
/usr/bin/az cloud set -n azurecloud
Done setting cloud: "azurecloud"
Login successful.

注:错误提示中提到的runner安装Azure CLI并非问题,使用的是同一台runner机器,同仓库调用时无需安装Azure CLI即可成功运行。

实际原因

跨仓库调用可复用工作流时,工作流的执行上下文属于调用方仓库,而非存储可复用工作流的BuildTemplate仓库。GitHub Actions的仓库级Secrets(Repository Secrets)是严格仓库隔离的,只有在本仓库触发的工作流才能直接读取自身的Secrets。

当可复用工作流中引用${{ secrets.AZURE_CLIENT_ID }}这类变量时,跨仓库场景下GitHub会尝试从调用方仓库的Secrets中取值,而非BuildTemplate仓库的。由于调用方仓库未配置这些Azure凭证Secrets,导致Azure/login@v1步骤无法获取有效认证信息,最终登录失败。

而同一仓库内调用时,工作流上下文属于BuildTemplate仓库本身,能够正常读取仓库内存储的Secrets,因此OIDC认证流程可以顺利获取令牌完成Azure登录。

内容的提问来源于stack exchange,提问作者user264953

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 20:15:19