GitHub Actions中Docker镜像执行EF迁移至Azure PostgreSQL认证失败
EF Core迁移在GitHub Actions中连接Azure PostgreSQL Flexible Server时密码认证失败
核心目标
在GitHub Actions的CI/CD工作流中,通过PR阶段构建的Docker镜像,将EF Core C#数据库迁移(创建/更新数据库/表)应用到Azure PostgreSQL Flexible Server。
问题现象
已成功连接到PostgreSQL服务器,但执行迁移时出现以下密码认证失败错误:
Npgsql.PostgresException (0x80004005): 28P01: password authentication failed for user "***" Exception data: Severity: FATAL SqlState: 28P01 MessageText: password authentication failed for user "***" File: auth.c Line: 418 Routine: auth_failed
执行的GitHub Actions代码
deploy-development: runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - name: Login to Azure uses: azure/login@v1 with: creds: ${{ secrets.DEV_AZURE_CREDENTIALS }} - name: Login to ACR (Development) run: az acr login --name myAzureContainerRegistry - name: Run Migrations (Development) run: | #1. Get the image that I have already built in previous step. docker pull myAzureContainerRegistry/dbmigrator:${{ github.sha }} #2. Create a connection string to pass into the migration container # so it can run it against Azure PostgreSQL server. connection_string="Server=myPostgreSQLServer.postgres.database.azure.com; Database=dbToBeCreatedByMigration;Port=5432; User Id=MyAdminUser;Password=LegalWorkingPassWord;Ssl Mode=Require; Trust Server Certificate=true;" #3. Run the migrations. This is where the error occurs docker run --rm \ -e ConnectionStrings:Default="$connection_string" \ myAzureContainerRegistry/dbmigrator:${{ github.sha }}
尝试过以下格式的连接字符串,同样无效:
connection_string="Host=${{ env.DEV_POSTGRESQL_SERVER_NAME }}.postgres.database.azure.com;Username=${{ env.DEV_POSTGRESQL_ADMIN_LOGIN }};Password=${{ env.DEV_POSTGRESQL_ADMIN_PASSWORD }};Database=${{ env.DEV_POSTGRESQL_DATABASE_NAME }};Ssl Mode=Require;Trust Server Certificate=true;"
已验证项
- 用户ID和密码正确:本地使用相同密码通过psql命令可正常连接,命令如下:
psql "--host=myPostgreSQLServer.postgres.database.azure.com" "--port=5432" "--dbname=postgres" "--username=MyAdminUser" "--set=sslmode=require" - PostgreSQL弹性服务器已添加GitHub Actions的所有必要IP作为防火墙规则,IP列表:
'192.30.252.0','185.199.108.0', '140.82.112.0', '143.55.64.0', '20.201.28.148', '20.205.243.168', '20.87.225.211', '20.248.137.49', '20.207.73.85', '20.27.177.116', '20.200.245.245','20.233.54.49' - PostgreSQL弹性服务器配置:已启用SSL/TLS;连接方式为公共访问(允许IP地址);已配置GitHub Actions的防火墙规则
- Azure日志无更多相关信息,查询语句如下:
let start_time = datetime("2023-07-28T07:42:08Z"); let end_time = datetime("2023-07-28T07:42:30Z"); AzureDiagnostics | where TimeGenerated >= start_time and TimeGenerated <= end_time | where Category == "PostgreSQLLogs" //| where Message contains "FATAL: password authentication failed for user" | project TimeGenerated, Message - Dockerfile无异常,内容如下:
FROM mcr.microsoft.com/dotnet/runtime:7.0 AS base WORKDIR /app FROM mcr.microsoft.com/dotnet/sdk:7.0 AS build WORKDIR /src COPY ["myProject/aNuGet.Config", "."] COPY ["myProject/myproject.DbMigrator.csproj", "myProject/myProject.DbMigrator/"] RUN dotnet restore "myProjectDbMigrator/myProjectDbMigrator.csproj" COPY . . WORKDIR "/myProjectDbMigrator" RUN dotnet build "myProject.DbMigrator.csproj" -c Release -o /app/build FROM build AS publish RUN dotnet publish "myProject.DbMigrator.csproj" -c Release -o /app/publish /p:UseAppHost=false FROM base AS final WORKDIR /app COPY --from=publish /app/publish . ENTRYPOINT ["dotnet", "myProjectDbMigrator.dll"]
技术栈
- .NET 7.0 Linux容器镜像
- Azure中Burstable类型PostgreSQL弹性服务器
- GitHub Actions
- abp.io框架
更新
原生EF Core可正常执行迁移,但在abp.io框架下出现该问题,已提交支持工单排查。
内容的提问来源于stack exchange,提问作者Sturla
相关产品推荐
相关产品推荐

