You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用google-github-actions部署Cloud Functions遇JWT签名无效错误

问题描述

尝试使用google-github-actions/deploy-cloud-functions工具部署Google Cloud Function,对应的YAML配置文件如下:

name: CI/CD Pipeline

on: push

env:
  PROJECT_PYTHON_VERSION: 3.10.10
  REGION: us-east1
jobs:
  deployment:
    runs-on: 'ubuntu-latest'
    permissions:
      contents: 'read'
      id-token: 'write'

    steps:
      - uses: actions/checkout@v3
      - id: auth
        name: Authenticate to Google Cloud
        uses: google-github-actions/auth@v1
        with:
          credentials_json: ${{ secrets.GOOGLE_CREDENTIALS }}

      - id: 'deploy'
        uses: 'google-github-actions/deploy-cloud-functions@v1'
        with:
            name: csat
            entry_point: nabla_events_consumer.csat.handle
            runtime: ${{ env.PROJECT_PYTHON_VERSION }}
            source_dir: ./

部署过程中遇到如下错误:

Error: google-github-actions/deploy-cloud-functions failed with: failed to upload zip file: invalid_grant: Invalid JWT Signature
排查与解决方法
  • 检查服务账号密钥有效性
    确认GitHub Secrets中GOOGLE_CREDENTIALS对应的服务账号密钥未过期、未被撤销。可在Google Cloud控制台的「IAM与管理」→「服务账号」页面找到对应账号,重新生成密钥并更新到GitHub Secrets。
  • 验证密钥格式完整性
    确保粘贴到GOOGLE_CREDENTIALS的是完整的JSON密钥内容,无多余换行、空格或截断。建议本地打开密钥JSON文件,全选复制后直接粘贴到Secrets中。
  • 确认服务账号权限
    服务账号需具备Cloud Functions Developer(部署函数)和Storage Object Admin(上传部署包至GCS)的角色。在Google Cloud控制台为对应服务账号添加这两个角色。
  • 调整认证配置
    使用credentials_json认证时,无需依赖OIDC的id-token: write权限,可尝试移除job中的permissions配置;或切换为OIDC认证模式(使用workload_identity_provider和service_account参数),避免两种认证逻辑冲突。
  • 修正Python Runtime格式
    Cloud Functions要求Python runtime格式为python310而非3.10.10,将PROJECT_PYTHON_VERSION的值改为python310,避免runtime识别错误引发后续问题。

内容的提问来源于stack exchange,提问作者p.magalhaes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 08:12:21