如何在GitHub Action中通过Python连接Google Drive?
问题:GitHub Action通过OIDC认证后使用pydrive2连接Google Drive失败
我尝试创建一个GitHub Action,用于运行可访问Google Drive的Python脚本。在GitHub Action中使用OIDC进行Google Drive认证,但Python文件中用pydrive2连接Google时遇到问题,显然Python端的认证方式有误。原本期望GitHub OIDC生成的凭据文件可直接用于认证,但实际运行时出错。
GitHub Action配置
name: 'Test Auth' on: [workflow_dispatch, push] jobs: ExploreActions: permissions: contents: 'read' id-token: 'write' runs-on: ubuntu-latest steps: # actions/checkout MUST come before auth - uses: 'actions/checkout@v3' with: ref: ${{ github.ref }} - name: 'Authenticate to Google Cloud' uses: 'google-github-actions/auth@v1' with: workload_identity_provider: 'projects/###############/locations/global/workloadIdentityPools/my-pool/providers/my-provider' service_account: '<user>@<service>.iam.gserviceaccount.com' create_credentials_file: true - name: Install Python uses: actions/setup-python@v4 with: python-version: '3.11' - name: Install Dependencies run: pip install pydrive2 shell: bash - name: Test python run: python experimental/test_action.py shell: bash
原Python代码
from pydrive2.auth import GoogleAuth from pydrive2.drive import GoogleDrive import os creds = os.environ.get("GOOGLE_APPLICATION_CREDENTIALS") print(creds) gauth = GoogleAuth() gauth.LoadCredentialsFile(creds) gauth.LocalWebserverAuth() drive = GoogleDrive(gauth)
运行错误输出(简化版)
2023-06-13T19:52:03.2759862Z Requested labels: ubuntu-latest 2023-06-13T19:52:14.2353436Z ##[group]Run google-github-actions/auth@v1 2023-06-13T19:52:14.2353828Z with: 2023-06-13T19:52:14.2354261Z workload_identity_provider: projects/########/locations/global/workloadIdentityPools/my-pool/providers/my-provider 2023-06-13T19:52:14.2354906Z service_account: xxxxxxxxx 2023-06-13T19:52:14.2355322Z create_credentials_file: true 2023-06-13T19:52:14.2355641Z export_environment_variables: true 2023-06-13T19:52:14.2355973Z cleanup_credentials: true 2023-06-13T19:52:14.2356231Z access_token_lifetime: 3600s 2023-06-13T19:52:14.2356660Z access_token_scopes: https://www.googleapis.com/auth/cloud-platform 2023-06-13T19:52:14.2357018Z retries: 3 2023-06-13T19:52:14.2357239Z backoff: 250 2023-06-13T19:52:14.2357534Z id_token_include_email: false 2023-06-13T19:52:14.2357818Z ##[endgroup] 2023-06-13T19:52:14.4899340Z Created credentials file at "/home/runner/work/small_projects/small_projects/gha-creds-e6ba77a2da78ef5b.json" 2023-06-13T19:52:14.5123821Z ##[group]Run actions/setup-python@v4 2023-06-13T19:52:23.2009265Z pythonLocation: /opt/hostedtoolcache/Python/3.11.4/x64 2023-06-13T19:52:23.2009636Z PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.11.4/x64/lib/pkgconfig 2023-06-13T19:52:23.2010012Z Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.4/x64 2023-06-13T19:52:23.2010370Z Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.4/x64 2023-06-13T19:52:23.2010724Z Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.4/x64 2023-06-13T19:52:23.2011067Z LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.11.4/x64/lib 2023-06-13T19:52:23.2011362Z ##[endgroup] 2023-06-13T19:52:23.6651848Z /home/runner/work/small_projects/small_projects/gha-creds-e6ba77a2da78ef5b.json 2023-06-13T19:52:23.6654092Z Traceback (most recent call last): 2023-06-13T19:52:23.6665200Z File "/home/runner/work/small_projects/small_projects/experimental/test_action.py", line 9, in <module> 2023-06-13T19:52:23.6668147Z gauth.LoadCredentialsFile(creds) 2023-06-13T19:52:23.6670573Z File "/opt/hostedtoolcache/Python/3.11.4/x64/lib/python3.11/site-packages/pydrive2/auth.py", line 418, in LoadCredentialsFile 2023-06-13T19:52:23.6673662Z self.credentials = self._default_storage.get() 2023-06-13T19:52:23.6675655Z ^^^^^^^^^^^^^^^^^^^^^^^^^^^ 2023-06-13T19:52:23.6677537Z File "/opt/hostedtoolcache/Python/3.11.4/x64/lib/python3.11/site-packages/oauth2client/client.py", line 407, in get 2023-06-13T19:52:23.6680768Z return self.locked_get() 2023-06-13T19:52:23.6688395Z ^^^^^^^^^^^^^^^^^ 2023-06-13T19:52:23.6690735Z File "/opt/hostedtoolcache/Python/3.11.4/x64/lib/python3.11/site-packages/oauth2client/file.py", line 54, in locked_get 2023-06-13T19:52:23.6693956Z credentials = client.Credentials.new_from_json(content) 2023-06-13T19:52:23.6696512Z ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ 2023-06-13T19:52:23.6698658Z File "/opt/hostedtoolcache/Python/3.11.4/x64/lib/python3.11/site-packages/oauth2client/client.py", line 302, in new_from_json 2023-06-13T19:52:23.6702354Z module_name = data['_module'] 2023-06-13T19:52:23.6704914Z ~~~~^^^^^^^^^^^ 2023-06-13T19:52:23.6706966Z KeyError: '_module' 2023-06-13T19:52:23.7152157Z ##[error]Process completed with exit code 1.
解决方法
改用Google Auth API实现认证连接,注意必须将Google Drive中需要访问的文件共享给对应的服务账号,才能正常获取文件列表。
修改后的Python代码:
import os import google.auth import googleapiclient.discovery creds, project = google.auth.default(scopes=['https://www.googleapis.com/auth/drive.readonly']) service = googleapiclient.discovery.build('drive', 'v3', credentials=creds) results = service.files().list( pageSize=10, fields="nextPageToken, files(id, name)").execute() items = results.get('files', []) print(items)
内容的提问来源于stack exchange,提问作者Thaqor
相关产品推荐
相关产品推荐

