You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Github Workflows:如何在部署环节添加手动确认步骤

GitHub Actions 部署环节添加手动确认步骤实现方案

问题描述

当前Workflow运行逻辑为:并行执行单元测试与集成测试,两者均通过后自动部署至Staging和Production环境。需求是在部署环节添加手动确认步骤,避免每次自动部署到Staging环境。

原配置文件

test.yml

name: Test, Build

on:
  workflow_call:

jobs:
  all-tests:
    name: All Tests
    runs-on: [self-hosted]
    services:
      postgres:
        image: postgres:11.5-alpine
        env:
          POSTGRES_USER: ''
          POSTGRES_PASSWORD: ''
          POSTGRES_DB: ''
        ports:
          - 5445:5432
        options: --health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5
    steps:
      - name: Checkout Repo
        uses: actions/checkout@master
      - name: Run migrations
        env:
          ENVIRONMENT: 'test'
          DATABASE_URL: ''
        run: ./gradlew flywayMigrate
      - name: Integration Test
        env:
          ENVIRONMENT: 'test'
        run: ./gradlew test

deploy.yml

name: Deploy

on:
  push:
    branches:
      - main

jobs:
  test:
    uses: ./.github/workflows/test.yml
  deploy-staging:
    name: Deploy Staging
    runs-on: [self-hosted]
    needs: [test]
    steps:
      - name: Checkout Repo
        uses: actions/checkout@master
      - name: Migrations
        env:
          ENVIRONMENT: 'staging'
          DATABASE_URL: ${{ secrets.DATABASE_URL_STAGING_MIGRATION }}
        run: ./gradlew flywayMigrate
      - name: Authenticate
        with:
          credentials_json: '${{ secrets.GCP_SA_KEY_STAGING }}'
        uses: 'google-github-actions/auth@v0'
      - name: Print Config Files
        env:
          ENVIRONMENT: 'staging'
        run: ./gradlew appengineShowConfiguration
      - name: Stage Deploy
        env:
          ENVIRONMENT: 'staging'
          DATABASE_URL: ${{ secrets.DATABASE_URL_STAGING }}
        run: ./gradlew appengineDeploy
  deploy-prod:
    name: Deploy Prod
    runs-on: [self-hosted]
    needs: [test]
    steps:
      - name: Checkout Repo
        uses: actions/checkout@master
      - name: Migrations
        env:
          ENVIRONMENT: 'production'
          DATABASE_URL: ${{ secrets.DATABASE_URL_MIGRATION }}
        run: ./gradlew flywayMigrate
      - name: Authenticate
        with:
          credentials_json: '${{ secrets.GCP_SA_KEY }}'
        uses: 'google-github-actions/auth@v0'
      - name: Print Config Files
        env:
          ENVIRONMENT: 'production'
        run: ./gradlew appengineShowConfiguration
      - name: Deploy
        env:
          ENVIRONMENT: 'production'
          DATABASE_URL: ${{ secrets.DATABASE_URL }}
        run: ./gradlew appengineDeploy

GitHub Workflow 测试与部署步骤

解决方案

利用GitHub Actions的环境审批机制,为部署任务绑定指定环境并配置手动审批规则,即可实现测试通过后需人工确认才执行部署。

修改后的deploy.yml配置

name: Deploy

on:
  push:
    branches:
      - main

jobs:
  test:
    uses: ./.github/workflows/test.yml
  deploy-staging:
    name: Deploy Staging
    runs-on: [self-hosted]
    needs: [test]
    # 绑定staging环境,触发手动审批流程
    environment: staging
    steps:
      - name: Checkout Repo
        uses: actions/checkout@master
      - name: Migrations
        env:
          ENVIRONMENT: 'staging'
          DATABASE_URL: ${{ secrets.DATABASE_URL_STAGING_MIGRATION }}
        run: ./gradlew flywayMigrate
      - name: Authenticate
        with:
          credentials_json: '${{ secrets.GCP_SA_KEY_STAGING }}'
        uses: 'google-github-actions/auth@v0'
      - name: Print Config Files
        env:
          ENVIRONMENT: 'staging'
        run: ./gradlew appengineShowConfiguration
      - name: Stage Deploy
        env:
          ENVIRONMENT: 'staging'
          DATABASE_URL: ${{ secrets.DATABASE_URL_STAGING }}
        run: ./gradlew appengineDeploy
  deploy-prod:
    name: Deploy Prod
    runs-on: [self-hosted]
    # 可选:若需先完成Staging部署再部署Prod,修改依赖为deploy-staging
    needs: [deploy-staging]
    # 同样为Prod环境添加审批
    environment: production
    steps:
      - name: Checkout Repo
        uses: actions/checkout@master
      - name: Migrations
        env:
          ENVIRONMENT: 'production'
          DATABASE_URL: ${{ secrets.DATABASE_URL_MIGRATION }}
        run: ./gradlew flywayMigrate
      - name: Authenticate
        with:
          credentials_json: '${{ secrets.GCP_SA_KEY }}'
        uses: 'google-github-actions/auth@v0'
      - name: Print Config Files
        env:
          ENVIRONMENT: 'production'
        run: ./gradlew appengineShowConfiguration
      - name: Deploy
        env:
          ENVIRONMENT: 'production'
          DATABASE_URL: ${{ secrets.DATABASE_URL }}
        run: ./gradlew appengineDeploy

配置环境审批规则

  1. 打开GitHub仓库,进入「Settings」->「Environments」
  2. 点击「New environment」,输入环境名称(需与配置文件中的environment字段一致,如staging)
  3. 在「Protection rules」区域,勾选「Required reviewers」,添加需要审批的人员或团队
  4. 保存设置即可

此后,当Workflow运行到deploy-staging或deploy-prod任务时,会自动暂停并等待指定人员审批,审批通过后才会继续执行部署操作。

内容的提问来源于stack exchange,提问作者bpereira

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 14:45:16