如何配置GitHub Actions CI在开源PR工作流中安全使用环境密钥?
开源项目PR工作流中依赖私密密钥的CI测试最佳实践
GitHub官方规则明确:
在工作流中使用加密密钥
除GITHUB_TOKEN外,当工作流由复刻仓库触发时,密钥不会传递给运行器。
针对你的需求——项目成员PR自动执行密钥依赖测试、第三方PR人工审核后触发测试,同时解决自身复刻PR无法加载密钥的问题,以下是具体实践方案:
一、基于提交者身份区分测试逻辑
通过GitHub提供的author_association字段判断PR提交者身份(OWNER/MEMBER/CONTRIBUTOR等),自动为内部成员PR加载密钥,第三方PR仅运行无密钥依赖的基础测试。
修改后的test.yaml示例:
name: Run tests on: push: pull_request: types: [opened, synchronize, reopened] jobs: test: name: Run tests runs-on: ubuntu-latest # 仅内部成员PR加载测试环境密钥 environment: ${{ contains('OWNER,MEMBER', github.event.pull_request.author_association) && 'test_environment' || '' }} steps: - uses: actions/checkout@v3 - name: Set up Python 3.10 uses: actions/setup-python@v4 with: python-version: 3.10 - name: Install package and dependencies run: pip install .[test] # 内部成员PR运行全量测试(含密钥依赖) - name: Run full tests with API key if: contains('OWNER,MEMBER', github.event.pull_request.author_association) env: FOO_API_KEY: ${{ secrets.FOO_API_KEY }} run: python -m pytest . # 第三方PR仅运行单元测试(无密钥依赖) - name: Run basic unit tests if: !contains('OWNER,MEMBER', github.event.pull_request.author_association) run: python -m pytest tests/unit/
此方案能直接解决你自己提交PR的问题:作为仓库OWNER,author_association值为OWNER,工作流会自动加载环境密钥。
二、人工触发第三方PR的全量测试
对于第三方贡献的PR,在代码审核通过后,可通过标签或评论指令触发含密钥的全量测试。
方式1:标签触发
为工作流添加标签触发规则,审核后添加指定标签即可启动全量测试:
name: Run tests on: push: pull_request: types: [opened, synchronize, reopened, labeled] jobs: test: name: Run tests runs-on: ubuntu-latest environment: ${{ (contains('OWNER,MEMBER', github.event.pull_request.author_association) || contains(github.event.pull_request.labels.*.name, 'run-full-tests')) && 'test_environment' || '' }} steps: - uses: actions/checkout@v3 - name: Set up Python 3.10 uses: actions/setup-python@v4 with: python-version: 3.10 - name: Install package and dependencies run: pip install .[test] - name: Run full tests with API key if: contains('OWNER,MEMBER', github.event.pull_request.author_association) || contains(github.event.pull_request.labels.*.name, 'run-full-tests') env: FOO_API_KEY: ${{ secrets.FOO_API_KEY }} run: python -m pytest . - name: Run basic unit tests if: ! (contains('OWNER,MEMBER', github.event.pull_request.author_association) || contains(github.event.pull_request.labels.*.name, 'run-full-tests')) run: python -m pytest tests/unit/
使用时,给第三方PR添加run-full-tests标签即可触发全量测试。
方式2:评论指令触发
通过监听PR评论,仅允许仓库所有者触发全量测试:
name: Run full tests on comment on: issue_comment: types: [created] jobs: test: # 仅仓库所有者评论/run-full-tests时触发 if: github.event.issue.pull_request && contains(github.event.comment.body, '/run-full-tests') && github.event.comment.author_association == 'OWNER' name: Run full tests runs-on: ubuntu-latest environment: test_environment steps: - uses: actions/checkout@v3 with: ref: ${{ github.event.issue.pull_request.head.sha }} - name: Set up Python 3.10 uses: actions/setup-python@v4 with: python-version: 3.10 - name: Install package and dependencies run: pip install .[test] - name: Run full tests with API key env: FOO_API_KEY: ${{ secrets.FOO_API_KEY }} run: python -m pytest . - name: Post test result uses: peter-evans/create-or-update-comment@v3 with: issue-number: ${{ github.event.issue.number }} body: | ✅ 全量测试已完成
使用时,在第三方PR下评论/run-full-tests即可触发测试。
三、利用环境审批规则控制密钥访问
针对test_environment环境设置审批规则,仅允许指定成员审批,实现所有PR需审批后才能加载密钥:
- 进入仓库Settings → Environments → 选择
test_environment - 在
Required reviewers中添加仓库成员团队/个人 - 可选:关闭
Wait timer,确保审批后立即运行
修改工作流,统一使用环境但依赖审批:
name: Run tests on: [push, pull_request] jobs: test: name: Run tests runs-on: ubuntu-latest environment: test_environment steps: - uses: actions/checkout@v3 - name: Set up Python 3.10 uses: actions/setup-python@v4 with: python-version: 3.10 - name: Install package and dependencies run: pip install .[test] - name: Run tests with API key env: FOO_API_KEY: ${{ secrets.FOO_API_KEY }} run: python -m pytest .
此方案下,内部成员PR可自行审批通过,第三方PR需指定成员审批后才能运行测试。
内容的提问来源于stack exchange,提问作者Ross Bencina
相关产品推荐
相关产品推荐

