You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置GitHub Actions CI在开源PR工作流中安全使用环境密钥?

开源项目PR工作流中依赖私密密钥的CI测试最佳实践

GitHub官方规则明确:

在工作流中使用加密密钥
除GITHUB_TOKEN外,当工作流由复刻仓库触发时,密钥不会传递给运行器。

针对你的需求——项目成员PR自动执行密钥依赖测试、第三方PR人工审核后触发测试,同时解决自身复刻PR无法加载密钥的问题,以下是具体实践方案:

一、基于提交者身份区分测试逻辑

通过GitHub提供的author_association字段判断PR提交者身份(OWNER/MEMBER/CONTRIBUTOR等),自动为内部成员PR加载密钥,第三方PR仅运行无密钥依赖的基础测试。

修改后的test.yaml示例:

name: Run tests

on:
  push:
  pull_request:
    types: [opened, synchronize, reopened]

jobs:
  test:
    name: Run tests
    runs-on: ubuntu-latest
    # 仅内部成员PR加载测试环境密钥
    environment: ${{ contains('OWNER,MEMBER', github.event.pull_request.author_association) && 'test_environment' || '' }}
    steps:
      - uses: actions/checkout@v3
      - name: Set up Python 3.10
        uses: actions/setup-python@v4
        with:
          python-version: 3.10
      - name: Install package and dependencies
        run: pip install .[test]
      
      # 内部成员PR运行全量测试(含密钥依赖)
      - name: Run full tests with API key
        if: contains('OWNER,MEMBER', github.event.pull_request.author_association)
        env:
          FOO_API_KEY: ${{ secrets.FOO_API_KEY }}
        run: python -m pytest .
      
      # 第三方PR仅运行单元测试(无密钥依赖)
      - name: Run basic unit tests
        if: !contains('OWNER,MEMBER', github.event.pull_request.author_association)
        run: python -m pytest tests/unit/

此方案能直接解决你自己提交PR的问题:作为仓库OWNER,author_association值为OWNER,工作流会自动加载环境密钥。

二、人工触发第三方PR的全量测试

对于第三方贡献的PR,在代码审核通过后,可通过标签或评论指令触发含密钥的全量测试。

方式1:标签触发

为工作流添加标签触发规则,审核后添加指定标签即可启动全量测试:

name: Run tests

on:
  push:
  pull_request:
    types: [opened, synchronize, reopened, labeled]

jobs:
  test:
    name: Run tests
    runs-on: ubuntu-latest
    environment: ${{ (contains('OWNER,MEMBER', github.event.pull_request.author_association) || contains(github.event.pull_request.labels.*.name, 'run-full-tests')) && 'test_environment' || '' }}
    steps:
      - uses: actions/checkout@v3
      - name: Set up Python 3.10
        uses: actions/setup-python@v4
        with:
          python-version: 3.10
      - name: Install package and dependencies
        run: pip install .[test]
      
      - name: Run full tests with API key
        if: contains('OWNER,MEMBER', github.event.pull_request.author_association) || contains(github.event.pull_request.labels.*.name, 'run-full-tests')
        env:
          FOO_API_KEY: ${{ secrets.FOO_API_KEY }}
        run: python -m pytest .
      
      - name: Run basic unit tests
        if: ! (contains('OWNER,MEMBER', github.event.pull_request.author_association) || contains(github.event.pull_request.labels.*.name, 'run-full-tests'))
        run: python -m pytest tests/unit/

使用时,给第三方PR添加run-full-tests标签即可触发全量测试。

方式2:评论指令触发

通过监听PR评论,仅允许仓库所有者触发全量测试:

name: Run full tests on comment

on:
  issue_comment:
    types: [created]

jobs:
  test:
    # 仅仓库所有者评论/run-full-tests时触发
    if: github.event.issue.pull_request && contains(github.event.comment.body, '/run-full-tests') && github.event.comment.author_association == 'OWNER'
    name: Run full tests
    runs-on: ubuntu-latest
    environment: test_environment
    steps:
      - uses: actions/checkout@v3
        with:
          ref: ${{ github.event.issue.pull_request.head.sha }}
      - name: Set up Python 3.10
        uses: actions/setup-python@v4
        with:
          python-version: 3.10
      - name: Install package and dependencies
        run: pip install .[test]
      - name: Run full tests with API key
        env:
          FOO_API_KEY: ${{ secrets.FOO_API_KEY }}
        run: python -m pytest .
      - name: Post test result
        uses: peter-evans/create-or-update-comment@v3
        with:
          issue-number: ${{ github.event.issue.number }}
          body: |
            ✅ 全量测试已完成

使用时,在第三方PR下评论/run-full-tests即可触发测试。

三、利用环境审批规则控制密钥访问

针对test_environment环境设置审批规则,仅允许指定成员审批,实现所有PR需审批后才能加载密钥:

  1. 进入仓库Settings → Environments → 选择test_environment
  2. 在Required reviewers中添加仓库成员团队/个人
  3. 可选:关闭Wait timer,确保审批后立即运行

修改工作流,统一使用环境但依赖审批:

name: Run tests

on: [push, pull_request]

jobs:
  test:
    name: Run tests
    runs-on: ubuntu-latest
    environment: test_environment
    steps:
      - uses: actions/checkout@v3
      - name: Set up Python 3.10
        uses: actions/setup-python@v4
        with:
          python-version: 3.10
      - name: Install package and dependencies
        run: pip install .[test]
      - name: Run tests with API key
        env:
          FOO_API_KEY: ${{ secrets.FOO_API_KEY }}
        run: python -m pytest .

此方案下,内部成员PR可自行审批通过,第三方PR需指定成员审批后才能运行测试。

内容的提问来源于stack exchange,提问作者Ross Bencina

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 03:09:59