使用GitHub REST API创建Actions密钥时值为空的解决咨询
如何通过GitHub REST API正确存储GitHub Actions密钥?
问题描述
通过GitHub REST API创建Actions密钥时,密钥能成功创建但值为空;但通过GitHub Actions网页UI手动创建时,值可正常存储并在脚本中使用。
用户使用的API调用:
curl -L \ -X PUT \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2022-11-28" \ https://api.github.com/repos/OWNER/REPO/actions/secrets/SECRET_NAME \ -d '{"encrypted_value":"c2VjcmV0","key_id":"012345678912345678"}'
加密encrypted_value的代码:
const sodium = require('libsodium-wrappers') const secret = 'plain-text-secret' // replace with the secret you want to encrypt const key = 'base64-encoded-public-key' // replace with the Base64 encoded public key //Check if libsodium is ready and then proceed. sodium.ready.then(() => { // Convert Secret & Base64 key to Uint8Array. let binkey = sodium.from_base64(key, sodium.base64_variants.ORIGINAL) let binsec = sodium.from_string(secret) //Encrypt the secret using LibSodium let encBytes = sodium.crypto_box_seal(binsec, binkey) // Convert encrypted Uint8Array to Base64 let output = sodium.to_base64(encBytes, sodium.base64_variants.ORIGINAL) console.log(output) });
解决步骤
1. 获取目标仓库的Actions公钥
必须使用对应仓库的专属Actions公钥,不能用其他公钥。通过以下API获取:
curl -L \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2022-11-28" \ https://api.github.com/repos/OWNER/REPO/actions/secrets/public-key
返回结果包含key(base64编码的公钥)和key_id,这两个值必须配对使用。
2. 正确加密密钥值
确保加密过程严格符合GitHub的要求,修正后的加密代码:
const sodium = require('libsodium-wrappers'); async function encryptGitHubSecret() { await sodium.ready; // 替换为从API获取的公钥 const repoPublicKey = '从API获取的base64公钥'; // 替换为你要存储的明文密钥 const secretPlaintext = 'your-secret-value'; // 转换公钥为Uint8Array const keyBytes = sodium.from_base64(repoPublicKey, sodium.base64_variants.ORIGINAL); // 转换明文密钥为Uint8Array const secretBytes = sodium.from_string(secretPlaintext); // 使用crypto_box_seal进行密封加密(GitHub要求的加密方式) const encryptedBytes = sodium.crypto_box_seal(secretBytes, keyBytes); // 转换为标准base64字符串 const encryptedValue = sodium.to_base64(encryptedBytes, sodium.base64_variants.ORIGINAL); console.log('加密后的值:', encryptedValue); console.log('对应的key_id: 从公钥API获取的key_id'); } encryptGitHubSecret();
3. 发送正确的API请求
确保encrypted_value和key_id是配对的最新值,且JSON格式无错误:
curl -L \ -X PUT \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2022-11-28" \ https://api.github.com/repos/OWNER/REPO/actions/secrets/SECRET_NAME \ -d '{ "encrypted_value": "上面生成的加密base64字符串", "key_id": "从公钥API获取的key_id" }'
常见错误排查
- 公钥不匹配:使用了错误的公钥(如用户SSH公钥、其他仓库的公钥),必须用当前仓库的Actions公钥。
- base64变体错误:GitHub要求使用标准base64(
ORIGINAL),不要使用URL安全的变体。 - JSON格式错误:请求体的JSON存在语法错误(如遗漏逗号、引号不匹配),导致GitHub无法解析
encrypted_value。 - 令牌权限不足:个人访问令牌(PAT)需要具备
repo(私有仓库)或public_repo(公共仓库)权限,且启用了Actions相关权限。
内容的提问来源于stack exchange,提问作者sagar chavan
相关产品推荐
相关产品推荐

