Azure静态Web App合并GitHub PR失败:提示deployment_token未提供
我们有一个纯HTML/JS静态Web应用,向main分支推送代码时,能通过.github/workflows/azurexxx.yaml自动部署到Azure静态Web App,流程正常。但创建或更新Pull Request(PR)时,Azure Static Web Apps CI/CD / Build and Deploy Job (pull_request)会执行48秒后失败,报错如下:
Run Azure/static-web-apps-deploy@v1 /usr/bin/docker run --name c9a4a5a9e299732ab04 LOTS OF STUFF DeploymentId: 5babc754-54b0-4694-9e7d-xxxxx deployment_token was not provided. The deployment_token is required for deploying content. If you'd like to continue the run without deployment, add the configuration skip_deploy_on_missing_secrets set to true in your workflow file An unknown exception has occurred
我们的疑问:
- 为什么PR流程会触发部署?我们只有生产环境的静态Web App,没有测试环境可部署。
- 如何让GitHub在PR时不执行构建/部署,只完成合并,合并后再触发已验证的部署流程?
- 报错提示要设置
skip_deploy_on_missing_secrets: true,这个配置该加在什么位置?是否需要修改PR对应的配置?
当前使用的YAML配置文件如下:
name: Azure Static Web Apps CI/CD on: push: branches: - main pull_request: types: [opened, synchronize, reopened, closed] branches: - main jobs: build_and_deploy_job: if: github.event_name == 'push' || (github.event_name == 'pull_request' && github.event.action != 'closed') runs-on: ubuntu-latest name: Build and Deploy Job steps: - uses: actions/checkout@v3 with: submodules: true - name: Build And Deploy id: builddeploy uses: Azure/static-web-apps-deploy@v1 with: azure_static_web_apps_api_token: ${{ secrets.AZURE_STATIC_WEB_APPS_API_TOKEN_WONDERFUL_PLANT_00xxxx }} repo_token: ${{ secrets.GITHUB_TOKEN }} # Used for Github integrations (i.e. PR comments) action: "upload" ###### Repository/Build Configurations - These values can be configured to match your app requirements. ###### # For more information regarding Static Web App workflow configurations, please visit: https://aka.ms/swaworkflowconfig app_location: "/" # App source code path api_location: "" # Api source code path - optional output_location: "/" # Built app content directory - optional ###### End of Repository/Build Configurations ###### close_pull_request_job: if: github.event_name == 'pull_request' && github.event.action == 'closed' runs-on: ubuntu-latest name: Close Pull Request Job steps: - name: Close Pull Request id: closepullrequest uses: Azure/static-web-apps-deploy@v1 with: azure_static_web_apps_api_token: ${{ secrets.AZURE_STATIC_WEB_APPS_API_TOKEN_WONDERFUL_PLANT_00xxxx }} action: "close"
1. PR触发部署的原因
你的Workflow配置中,on字段明确包含了pull_request事件(覆盖opened、synchronize、reopened、closed四种动作),同时build_and_deploy_job的条件判断允许PR事件(除closed动作外)触发任务执行。Azure Static Web Apps默认会在PR触发时尝试部署到预览环境,但你没有配置预览环境的token,所以抛出deployment_token was not provided的错误。
2. 让PR不执行构建/部署的方法
直接修改Workflow的触发规则和任务执行条件,彻底移除PR事件的触发逻辑:
- 删除
on字段下的整个pull_request配置块,这样只有向main分支推送代码时才会触发部署流程。 - 同时删除
close_pull_request_job(因为不需要再处理PR关闭的动作)。
修改后的核心配置示例:
on: push: branches: - main jobs: build_and_deploy_job: if: github.event_name == 'push' runs-on: ubuntu-latest name: Build and Deploy Job # 后续步骤保持原配置不变
这样PR创建或更新时不会触发任何构建部署任务,只有当PR合并到main分支后,push事件会自动触发已验证通过的生产环境部署流程。
3. skip_deploy_on_missing_secrets的配置位置(若需保留PR触发但不部署)
如果不想完全移除PR触发,只是希望PR时仅执行构建但跳过部署,需要将该参数添加到Azure/static-web-apps-deploy步骤的with配置块中,针对PR场景生效:
- 在
build_and_deploy_job的Build And Deploy步骤里,新增skip_deploy_on_missing_secrets: true配置项。
修改后的步骤示例:
- name: Build And Deploy id: builddeploy uses: Azure/static-web-apps-deploy@v1 with: azure_static_web_apps_api_token: ${{ secrets.AZURE_STATIC_WEB_APPS_API_TOKEN_WONDERFUL_PLANT_00xxxx }} repo_token: ${{ secrets.GITHUB_TOKEN }} action: "upload" skip_deploy_on_missing_secrets: true # 新增配置 app_location: "/" api_location: "" output_location: "/"
不过更推荐直接移除PR触发配置,因为你不需要预览环境,这样配置更简洁,也能避免不必要的任务执行开销。
内容的提问来源于stack exchange,提问作者John Little

