You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions中Docker镜像执行EF迁移至Azure PostgreSQL认证失败

EF Core迁移在GitHub Actions中连接Azure PostgreSQL Flexible Server时密码认证失败

核心目标

在GitHub Actions的CI/CD工作流中,通过PR阶段构建的Docker镜像,将EF Core C#数据库迁移(创建/更新数据库/表)应用到Azure PostgreSQL Flexible Server。

问题现象

已成功连接到PostgreSQL服务器,但执行迁移时出现以下密码认证失败错误:

Npgsql.PostgresException (0x80004005): 28P01: password authentication failed for user "***"

  Exception data:
    Severity: FATAL
    SqlState: 28P01
    MessageText: password authentication failed for user "***"
    File: auth.c
    Line: 418
    Routine: auth_failed

执行的GitHub Actions代码

deploy-development:
  runs-on: ubuntu-latest
  steps:
  - uses: actions/checkout@v3

  - name: Login to Azure
    uses: azure/login@v1
    with:
      creds: ${{ secrets.DEV_AZURE_CREDENTIALS }}

  - name: Login to ACR (Development)
    run: az acr login --name myAzureContainerRegistry

  - name: Run Migrations (Development)
    run: |

      #1.  Get the image that I have already built in previous step.
      docker pull myAzureContainerRegistry/dbmigrator:${{ github.sha }}
          
      #2. Create a connection string to pass into the migration container 
      #    so it can run it against Azure PostgreSQL server.

      connection_string="Server=myPostgreSQLServer.postgres.database.azure.com;
      Database=dbToBeCreatedByMigration;Port=5432;
      User Id=MyAdminUser;Password=LegalWorkingPassWord;Ssl Mode=Require;
      Trust Server Certificate=true;"

      #3. Run the migrations. This is where the error occurs 
      docker run --rm \
      -e ConnectionStrings:Default="$connection_string" \
      myAzureContainerRegistry/dbmigrator:${{ github.sha }}

尝试过以下格式的连接字符串,同样无效:

connection_string="Host=${{ env.DEV_POSTGRESQL_SERVER_NAME }}.postgres.database.azure.com;Username=${{ env.DEV_POSTGRESQL_ADMIN_LOGIN }};Password=${{ env.DEV_POSTGRESQL_ADMIN_PASSWORD }};Database=${{ env.DEV_POSTGRESQL_DATABASE_NAME }};Ssl Mode=Require;Trust Server Certificate=true;"

已验证项

  • 用户ID和密码正确:本地使用相同密码通过psql命令可正常连接,命令如下:
    psql "--host=myPostgreSQLServer.postgres.database.azure.com" "--port=5432" "--dbname=postgres" "--username=MyAdminUser" "--set=sslmode=require"
    
  • PostgreSQL弹性服务器已添加GitHub Actions的所有必要IP作为防火墙规则,IP列表:'192.30.252.0','185.199.108.0', '140.82.112.0', '143.55.64.0', '20.201.28.148', '20.205.243.168', '20.87.225.211', '20.248.137.49', '20.207.73.85', '20.27.177.116', '20.200.245.245','20.233.54.49'
  • PostgreSQL弹性服务器配置:已启用SSL/TLS;连接方式为公共访问(允许IP地址);已配置GitHub Actions的防火墙规则
  • Azure日志无更多相关信息,查询语句如下:
    let start_time = datetime("2023-07-28T07:42:08Z");
    let end_time = datetime("2023-07-28T07:42:30Z");
    AzureDiagnostics
    | where TimeGenerated >= start_time and TimeGenerated <= end_time
    | where Category == "PostgreSQLLogs"
    //| where Message contains "FATAL:  password authentication failed for user"
    | project TimeGenerated, Message
    
  • Dockerfile无异常,内容如下:
    FROM mcr.microsoft.com/dotnet/runtime:7.0 AS base
    WORKDIR /app
    
    FROM mcr.microsoft.com/dotnet/sdk:7.0 AS build
    WORKDIR /src
    COPY ["myProject/aNuGet.Config", "."]
    COPY ["myProject/myproject.DbMigrator.csproj", "myProject/myProject.DbMigrator/"]
    RUN dotnet restore "myProjectDbMigrator/myProjectDbMigrator.csproj"
    COPY . .
    WORKDIR "/myProjectDbMigrator"
    RUN dotnet build "myProject.DbMigrator.csproj" -c Release -o /app/build
    
    FROM build AS publish
    RUN dotnet publish "myProject.DbMigrator.csproj" -c Release -o /app/publish /p:UseAppHost=false
    
    FROM base AS final
    WORKDIR /app
    COPY --from=publish /app/publish .
    ENTRYPOINT ["dotnet", "myProjectDbMigrator.dll"]   
    

技术栈

  • .NET 7.0 Linux容器镜像
  • Azure中Burstable类型PostgreSQL弹性服务器
  • GitHub Actions
  • abp.io框架

更新

原生EF Core可正常执行迁移,但在abp.io框架下出现该问题,已提交支持工单排查。


内容的提问来源于stack exchange,提问作者Sturla

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 22:25:59