You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Github Actions中选取docker/metadata-action返回的指定标签子集

解决方案

你遇到的问题核心是 docker/metadata-action 的 outputs.labels 是格式化后的字符串,而非可直接访问的对象,所以无法通过点语法提取单个标签。以下两种方法可以实现只保留指定标签的需求:

方法一:直接在构建步骤中解析JSON输出

利用GitHub Actions的 fromJSON 函数解析 metadata-action 输出的完整JSON,直接提取需要的标签:

name: Build Docker Image and Publish to Registry

on:
  workflow_dispatch:
  push:
    branches:
      - main

permissions:
  contents: read
  packages: write

env:
  DOCKER_REGISTRY: ghcr.io
  DOCKER_IMAGE_NAME: ${{ github.repository }}

jobs:
  build-and-publish-docker-image:
    name: Build and publish the Docker image
    runs-on: ubuntu-latest
    steps:
      - name: Check out repository code
        uses: actions/checkout@v3

      - name: Set up QEMU
        uses: docker/setup-qemu-action@v2

      - name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v2

      - name: Login to Docker registry
        uses: docker/login-action@v2
        with:
          registry: ${{ env.DOCKER_REGISTRY }}
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}

      - name: Extract metadata (tags, labels) for Docker
        id: meta
        uses: docker/metadata-action@v4
        with:
          images: ${{ env.DOCKER_REGISTRY }}/${{ env.DOCKER_IMAGE_NAME }}
          tags: |
            type=ref,event=branch
            type=sha,event=workflow_dispatch

      - name: Build and push
        uses: docker/build-push-action@v4
        with:
          context: .
          file: ./Dockerfile
          tags: ${{ steps.meta.outputs.tags }}
          labels: |
            org.opencontainers.image.created=${{ fromJSON(steps.meta.outputs.json).labels['org.opencontainers.image.created'] }}
            org.opencontainers.image.revision=${{ fromJSON(steps.meta.outputs.json).labels['org.opencontainers.image.revision'] }}

方法二:添加步骤提取指定标签

通过 jq 工具解析JSON输出,先提取需要的标签并保存为步骤输出,再在构建步骤中引用:

name: Build Docker Image and Publish to Registry

on:
  workflow_dispatch:
  push:
    branches:
      - main

permissions:
  contents: read
  packages: write

env:
  DOCKER_REGISTRY: ghcr.io
  DOCKER_IMAGE_NAME: ${{ github.repository }}

jobs:
  build-and-publish-docker-image:
    name: Build and publish the Docker image
    runs-on: ubuntu-latest
    steps:
      - name: Check out repository code
        uses: actions/checkout@v3

      - name: Set up QEMU
        uses: docker/setup-qemu-action@v2

      - name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v2

      - name: Login to Docker registry
        uses: docker/login-action@v2
        with:
          registry: ${{ env.DOCKER_REGISTRY }}
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}

      - name: Extract metadata (tags, labels) for Docker
        id: meta
        uses: docker/metadata-action@v4
        with:
          images: ${{ env.DOCKER_REGISTRY }}/${{ env.DOCKER_IMAGE_NAME }}
          tags: |
            type=ref,event=branch
            type=sha,event=workflow_dispatch

      - name: Extract required labels
        id: filtered-labels
        run: |
          CREATED=$(echo '${{ steps.meta.outputs.json }}' | jq -r '.labels["org.opencontainers.image.created"]')
          REVISION=$(echo '${{ steps.meta.outputs.json }}' | jq -r '.labels["org.opencontainers.image.revision"]')
          echo "labels=org.opencontainers.image.created=${CREATED}
          org.opencontainers.image.revision=${REVISION}" >> $GITHUB_OUTPUT

      - name: Build and push
        uses: docker/build-push-action@v4
        with:
          context: .
          file: ./Dockerfile
          tags: ${{ steps.meta.outputs.tags }}
          labels: ${{ steps.filtered-labels.outputs.labels }}

两种方法都能实现只保留 org.opencontainers.image.created 和 org.opencontainers.image.revision 标签,其余标签使用Dockerfile中定义的默认值。

内容的提问来源于stack exchange,提问作者zaadeh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 23:34:57