如何访问GitHub Actions CI/CD运行器内的容器?
问题描述
我用GitHub Actions搭建CI/CD流水线部署PHP/MySQL应用,流水线执行完全正常,但没法访问运行器(runner)里的容器。我用以下脚本打印了运行器的公网IP:
ip=$(curl -s https://api.ipify.org)
得到的IP是40.77.93.7,但访问http://40.77.93.7:9090/或http://40.77.93.7:3000/时,页面提示:
This site can’t be reached 40.77.93.7 took too long to respond.
我的流水线配置、Dockerfile和docker-compose.yml如下:
流水线配置
name: CI/CD Pipeline on: push: branches: - main env: IMAGE_NAME: sens31/ehospital jobs: ip: runs-on: ubuntu-latest steps: - name: Get runner IP address run: | ip=$(curl -s https://api.ipify.org) for i in {1..10}; do echo "The IP address of the runner is: $ip" done build: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v2 - name: Log in to Docker Hub run: echo "${{ secrets.DOCKER_PASSWORD }}" | docker login -u ${{ secrets.DOCKER_USERNAME }} --password-stdin env: DOCKER_BUILDKIT: 1 - name: Build and push Docker image uses: docker/build-push-action@v2 with: context: . dockerfile: Dockerfile push: true tags: ${{ env.IMAGE_NAME }}:latest compose: needs: build runs-on: ubuntu-latest steps: - name: Clone repository run: git clone https://github.com/sensgithub/eHospital.git working-directory: ${{ github.workspace }} - name: Start services run: | cd eHospital docker-compose up -d # Prometheus prometheus: needs: build runs-on: ubuntu-latest steps: - name: Start Prometheus run: | docker run -d --name prometheus -p 9090:9090 prom/prometheus # Grafana grafana: needs: build runs-on: ubuntu-latest steps: - name: Start Grafana run: | docker run -d --name grafana -p 3000:3000 grafana/grafana
Dockerfile
FROM php:7.4-apache # Install required PHP extensions RUN apt-get update -y && apt-get install -y libmariadb-dev RUN docker-php-ext-install mysqli pdo pdo_mysql # Copy application files to the container COPY . /var/www/html/ # Copy Apache configuration file COPY apache.conf /etc/apache2/sites-available/000-default.conf # Enable Apache rewrite module RUN a2enmod rewrite # Install Docker Compose RUN apt-get update && \ apt-get install -y curl && \ curl -sSL https://get.docker.com/ | sh && \ curl -L https://github.com/docker/compose/releases/download/1.29.0/docker-compose-$(uname -s)-$(uname -m) -o /usr/local/bin/docker-compose && \ chmod +x /usr/local/bin/docker-compose # Set the working directory WORKDIR /var/www/html # Expose port 80 EXPOSE 80 # Start Apache server CMD ["/usr/sbin/apache2ctl", "-D", "FOREGROUND"]
docker-compose.yml
version: '3.9' services: db: image: mysql:latest environment: - MYSQL_DATABASE=ehospital - MYSQL_USER=ehospital - MYSQL_PASSWORD=root - MYSQL_ALLOW_EMPTY_PASSWORD=1 volumes: - "./db:/docker-entrypoint-initdb.d" # persistent db www: image: php:apache volumes: - "./:/var/www/html" ports: - 80:80 - 443:443 # for future ssl traffic phpmyadmin: image: phpmyadmin/phpmyadmin ports: - 8001:80 environment: - PMA_HOST=db - PMA_PORT=3306
解决思路
托管运行器的网络限制
GitHub提供的ubuntu-latest托管运行器是临时虚拟机,你拿到的公网IP是平台NAT后的地址,运行器内部的端口不会暴露到公网。这是平台的网络隔离机制,目的是保障运行器安全性,所以没法直接通过这个IP访问内部容器服务。任务隔离的问题
你的流水线里compose、prometheus、grafana是三个独立的job,每个job都会在全新的托管运行器实例上执行。也就是说,这三个job的容器分别跑在三个完全不同的虚拟机里,互相之间没有关联,自然没法通过同一个IP访问。正确的处理方向
- 不要用托管运行器对外提供服务:托管运行器是临时资源,任务结束后就会被销毁,不适合作为服务运行环境。应该把构建好的镜像部署到云服务器、K8s集群、Docker Swarm或者容器托管平台(比如AWS ECS、阿里云容器服务)。
- 内部验证服务状态:如果只是要验证容器是否能正常启动,可以把所有服务启动步骤放到同一个job里,然后在运行器内部用
curl、wget访问localhost对应的端口,验证服务是否正常,而不是尝试从外部访问公网IP。 - 合并分散的job:把
compose、prometheus、grafana的启动步骤合并到同一个job中,确保所有服务都运行在同一个运行器实例里,这样不仅能内部验证,服务之间也能正常通信。
流水线配置优化示例
调整后的job示例:deploy-and-verify: needs: build runs-on: ubuntu-latest steps: - name: Clone repository run: git clone https://github.com/sensgithub/eHospital.git working-directory: ${{ github.workspace }} - name: Start application services run: | cd eHospital docker-compose up -d - name: Start monitoring services run: | docker run -d --name prometheus -p 9090:9090 prom/prometheus docker run -d --name grafana -p 3000:3000 grafana/grafana - name: Wait for services to start run: sleep 30 # 根据服务启动时间调整 - name: Verify services are running run: | curl -I http://localhost:80 curl -I http://localhost:9090 curl -I http://localhost:3000
内容的提问来源于stack exchange,提问作者sens31
相关产品推荐
相关产品推荐

