GitHub Actions部署IIS遇权限错误:需提升进程权限访问IIS配置
问题:GitHub Actions部署IIS时权限不足错误
错误提示:
import-module : Process should have elevated status to access IIS configuration data
已尝试使用RunAs命令、修改注册表策略,但问题依旧。以下是当前使用的GitHub Workflow代码:
name: DEEEEDeploy to Development Environment on: push: branches: - master pull_request: branches: - PrepRod env: AZURE_DEVWEBAPP_NAME: GitAc-Dev AZURE_PREPRODWEBAPP_NAME: GitAc-PreProd AZURE_WEBAPP_PACKAGE_PATH: 'D:\a\GitNewTest2\GitNewTest2\GitNewTest2\bin' jobs: Build: runs-on: windows-latest steps: - uses: actions/checkout@v2 - name: Setup MSBuild uses: microsoft/setup-msbuild@v1 - name: Setup NuGet uses: NuGet/setup-nuget@v1.0.5 - name: Restore NuGet packages run: nuget restore GitNewTest2/GitNewTest2.sln - name: build run: | msbuild GitNewTest2/GitNewTest2.sln /t:Build /p:Configuration=Release /p:Platform="Any CPU" /verbosity:minimal - name: publish run: | msbuild GitNewTest2/GitNewTest2.sln /t:Publish /p:Configuration=Release /p:Platform="Any CPU" /p:PublishDir="./artifacts" - name: Upload artifacts uses: actions/upload-artifact@v2 with: name: myapp path: ${{env.AZURE_WEBAPP_PACKAGE_PATH}} - name: running1 run: | Get-location - name: running6 run: | dir D:\a\GitNewTest2\GitNewTest2\GitNewTest2\bin - name: Download artifacts uses: actions/download-artifact@v2 with: name: myapp path: 'C:\app.publish' - name: running run: | Get-location - name: running2 run: | dir - name: running3 run: | cd C:\app.publish dir DeployDev: name: Dev needs: Build # if: github.event_name == 'refs/heads/master' runs-on: self-hosted env: DEV_WEBSITE_NAME: ${{secrets.DEV_WEBSITE_NAME}} DEV_APP_POOL_NAME: ${{secrets.DEV_APP_POOL_NAME}} WEBAPP_MSDeploy_USERNAME: ${{secrets.IIS_USERNAME}} WEBAPP_MSDeploy_PASSWORD: ${{secrets.IIS_PASSWORD}} environment: name: Dev steps: - name: Checkout Code uses: actions/checkout@v2 - name: Download artifacts uses: actions/download-artifact@v2 with: name: myapp path: 'C:\app.publish' - name: copying run: | $path="${{github.workspace}}\GitNewTest2\Scripts\DevTestScript.ps1" echo $path & $path cd C:\inetpub\wwwroot\ dir Copy-Item C:\app.publish\* C:\inetpub\wwwroot\${{env.DEV_WEBSITE_NAME}} -Recurse -Force - name: create new apppool run: | Start-Process powershell.exe -Verb RunAs -ArgumentList "-File C:\actions-runner\_work\GitNewTest2\GitNewTest2\GitNewTest2\Scripts\DevTestAppPool.ps1" # & C:\actions-runner\_work\GitNewTest2\GitNewTest2\GitNewTest2\Scripts\DevTestAppPool.ps1 - name: create website run: | & C:\actions-runner\_work\GitNewTest2\GitNewTest2\GitNewTest2\Scripts\DevTestWebsite.ps1 - name: config to use new appool run: | Set-ItemProperty -Path "IIS:\Sites\${{env.DEV_WEBSITE_NAME}}" -Name "applicationPool" -Value ${{env.DEV_APP_POOL_NAME}} - name: Deploy to IIS run: | start-process PowerShell -verb runas iisreset /stop iisreset /start
核心问题分析
GitHub Actions自托管Runner默认没有以管理员权限运行,而操作IIS配置(创建应用池、网站、修改IIS:\路径属性等)必须具备管理员权限。当前配置的问题在于:
- 仅给部分命令加了
Start-Process -Verb RunAs,但后续依赖这些操作的命令(如修改应用池绑定)仍在普通权限进程中执行 - 单独启动管理员PowerShell进程不会让runner的后续步骤继承权限
具体修复方案
1. 确保自托管Runner以管理员身份启动
- 打开Windows服务管理器,找到
GitHub Actions Runner服务 - 右键选择「属性」→「登录」,选择拥有本地管理员权限的账户;若使用系统账户,勾选「允许服务与桌面交互」
- 重启该服务
2. 调整Workflow中需权限的步骤
将所有涉及IIS配置的命令,全部用管理员进程执行,并加上-Wait确保执行完成后再推进后续步骤:
修改create website步骤
- name: create website run: | Start-Process powershell.exe -Verb RunAs -ArgumentList "-File ${{github.workspace}}\GitNewTest2\Scripts\DevTestWebsite.ps1" -Wait
修改config to use new appool步骤
- name: config to use new appool run: | $cmd = "Set-ItemProperty -Path 'IIS:\Sites\${{env.DEV_WEBSITE_NAME}}' -Name 'applicationPool' -Value '${{env.DEV_APP_POOL_NAME}}'" Start-Process powershell.exe -Verb RunAs -ArgumentList "-Command $cmd" -Wait
修改Deploy to IIS步骤
- name: Deploy to IIS run: | Start-Process powershell.exe -Verb RunAs -ArgumentList "-Command 'iisreset /stop; iisreset /start'" -Wait
3. 清理冗余步骤
删除Build步骤中的Download artifacts相关操作,Build阶段仅需上传产物,DeployDev阶段已包含下载动作。
内容的提问来源于stack exchange,提问作者jackazjimmy
相关产品推荐
相关产品推荐

