You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions部署IIS遇权限错误:需提升进程权限访问IIS配置

问题:GitHub Actions部署IIS时权限不足错误

错误提示:

import-module : Process should have elevated status to access IIS configuration data

已尝试使用RunAs命令、修改注册表策略,但问题依旧。以下是当前使用的GitHub Workflow代码:

name: DEEEEDeploy to Development Environment
on:
push:
branches:
- master
pull_request:
branches:
- PrepRod
env:
AZURE_DEVWEBAPP_NAME: GitAc-Dev
AZURE_PREPRODWEBAPP_NAME: GitAc-PreProd
AZURE_WEBAPP_PACKAGE_PATH: 'D:\a\GitNewTest2\GitNewTest2\GitNewTest2\bin'
jobs:
Build:
runs-on: windows-latest
steps:
- uses: actions/checkout@v2
- name: Setup MSBuild
  uses: microsoft/setup-msbuild@v1
- name: Setup NuGet
  uses: NuGet/setup-nuget@v1.0.5
- name: Restore NuGet packages
  run: nuget restore GitNewTest2/GitNewTest2.sln
- name: build
  run: |
       msbuild GitNewTest2/GitNewTest2.sln /t:Build /p:Configuration=Release /p:Platform="Any CPU" /verbosity:minimal
- name: publish
  run: |
       msbuild GitNewTest2/GitNewTest2.sln /t:Publish /p:Configuration=Release /p:Platform="Any CPU" /p:PublishDir="./artifacts"
- name: Upload artifacts
  uses: actions/upload-artifact@v2
  with:
    name: myapp
    path: ${{env.AZURE_WEBAPP_PACKAGE_PATH}}
- name: running1
  run: |
Get-location
- name: running6
  run: |
dir D:\a\GitNewTest2\GitNewTest2\GitNewTest2\bin
- name: Download artifacts
  uses: actions/download-artifact@v2
  with:
    name: myapp
    path: 'C:\app.publish'
- name: running
  run: |
Get-location
- name: running2
  run: |
dir
- name: running3
  run: |
cd C:\app.publish
dir
DeployDev:
  name: Dev
  needs: Build
  # if: github.event_name == 'refs/heads/master'
  runs-on: self-hosted
  env:
    DEV_WEBSITE_NAME: ${{secrets.DEV_WEBSITE_NAME}}
    DEV_APP_POOL_NAME: ${{secrets.DEV_APP_POOL_NAME}}
    WEBAPP_MSDeploy_USERNAME: ${{secrets.IIS_USERNAME}}
    WEBAPP_MSDeploy_PASSWORD: ${{secrets.IIS_PASSWORD}}
  environment:
      name: Dev
  steps:
    - name: Checkout Code 
      uses: actions/checkout@v2
    - name: Download artifacts
      uses: actions/download-artifact@v2
      with:
       name: myapp
       path: 'C:\app.publish'
    - name: copying
      run: |
           $path="${{github.workspace}}\GitNewTest2\Scripts\DevTestScript.ps1"
           echo $path
           & $path
           cd C:\inetpub\wwwroot\
           dir
           Copy-Item C:\app.publish\* C:\inetpub\wwwroot\${{env.DEV_WEBSITE_NAME}} -Recurse -Force
    - name: create new apppool
      run: |
          Start-Process powershell.exe -Verb RunAs -ArgumentList "-File C:\actions-runner\_work\GitNewTest2\GitNewTest2\GitNewTest2\Scripts\DevTestAppPool.ps1"
          # & C:\actions-runner\_work\GitNewTest2\GitNewTest2\GitNewTest2\Scripts\DevTestAppPool.ps1
    - name: create website
      run: |
        & C:\actions-runner\_work\GitNewTest2\GitNewTest2\GitNewTest2\Scripts\DevTestWebsite.ps1
    - name: config to use new appool
      run: |
       Set-ItemProperty -Path "IIS:\Sites\${{env.DEV_WEBSITE_NAME}}" -Name "applicationPool" -Value ${{env.DEV_APP_POOL_NAME}}
    - name: Deploy to IIS
      run: |
        start-process PowerShell -verb runas 
        iisreset /stop
        iisreset /start

核心问题分析

GitHub Actions自托管Runner默认没有以管理员权限运行,而操作IIS配置(创建应用池、网站、修改IIS:\路径属性等)必须具备管理员权限。当前配置的问题在于:

  1. 仅给部分命令加了Start-Process -Verb RunAs,但后续依赖这些操作的命令(如修改应用池绑定)仍在普通权限进程中执行
  2. 单独启动管理员PowerShell进程不会让runner的后续步骤继承权限

具体修复方案

1. 确保自托管Runner以管理员身份启动

  • 打开Windows服务管理器,找到GitHub Actions Runner服务
  • 右键选择「属性」→「登录」,选择拥有本地管理员权限的账户;若使用系统账户,勾选「允许服务与桌面交互」
  • 重启该服务

2. 调整Workflow中需权限的步骤

将所有涉及IIS配置的命令,全部用管理员进程执行,并加上-Wait确保执行完成后再推进后续步骤:

修改create website步骤

- name: create website
  run: |
    Start-Process powershell.exe -Verb RunAs -ArgumentList "-File ${{github.workspace}}\GitNewTest2\Scripts\DevTestWebsite.ps1" -Wait

修改config to use new appool步骤

- name: config to use new appool
  run: |
    $cmd = "Set-ItemProperty -Path 'IIS:\Sites\${{env.DEV_WEBSITE_NAME}}' -Name 'applicationPool' -Value '${{env.DEV_APP_POOL_NAME}}'"
    Start-Process powershell.exe -Verb RunAs -ArgumentList "-Command $cmd" -Wait

修改Deploy to IIS步骤

- name: Deploy to IIS
  run: |
    Start-Process powershell.exe -Verb RunAs -ArgumentList "-Command 'iisreset /stop; iisreset /start'" -Wait

3. 清理冗余步骤

删除Build步骤中的Download artifacts相关操作,Build阶段仅需上传产物,DeployDev阶段已包含下载动作。


内容的提问来源于stack exchange,提问作者jackazjimmy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 17:32:16