You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何访问GitHub Actions CI/CD运行器内的容器?

问题描述

我用GitHub Actions搭建CI/CD流水线部署PHP/MySQL应用,流水线执行完全正常,但没法访问运行器(runner)里的容器。我用以下脚本打印了运行器的公网IP:

ip=$(curl -s https://api.ipify.org)

得到的IP是40.77.93.7,但访问http://40.77.93.7:9090/或http://40.77.93.7:3000/时,页面提示:

This site can’t be reached 40.77.93.7 took too long to respond.

我的流水线配置、Dockerfile和docker-compose.yml如下:

流水线配置

name: CI/CD Pipeline

on:
  push:
    branches:
      - main

env:
  IMAGE_NAME: sens31/ehospital

jobs:
          
  ip:
    runs-on: ubuntu-latest
    steps:
      - name: Get runner IP address
        run: |
          ip=$(curl -s https://api.ipify.org)
          for i in {1..10}; do
            echo "The IP address of the runner is: $ip"
          done      
          
  build:
    runs-on: ubuntu-latest

    steps:
      - name: Checkout code
        uses: actions/checkout@v2
      
      - name: Log in to Docker Hub
        run: echo "${{ secrets.DOCKER_PASSWORD }}" | docker login -u ${{ secrets.DOCKER_USERNAME }} --password-stdin
        env:
          DOCKER_BUILDKIT: 1
      
      - name: Build and push Docker image
        uses: docker/build-push-action@v2
        with:
          context: .
          dockerfile: Dockerfile
          push: true
          tags: ${{ env.IMAGE_NAME }}:latest
          
  compose:
    needs: build
    runs-on: ubuntu-latest
    steps:
      - name: Clone repository
        run: git clone https://github.com/sensgithub/eHospital.git
        working-directory: ${{ github.workspace }}
      
      - name: Start services
        run: |
          cd eHospital
          docker-compose up -d

# Prometheus
  prometheus:
    needs: build
    runs-on: ubuntu-latest
    steps:
      - name: Start Prometheus
        run: |
          docker run -d --name prometheus -p 9090:9090 prom/prometheus

# Grafana 
  grafana:
    needs: build
    runs-on: ubuntu-latest
    steps:
      - name: Start Grafana
        run: |
          docker run -d --name grafana -p 3000:3000 grafana/grafana

Dockerfile

FROM php:7.4-apache

# Install required PHP extensions
RUN apt-get update -y && apt-get install -y libmariadb-dev
RUN docker-php-ext-install mysqli pdo pdo_mysql

# Copy application files to the container
COPY . /var/www/html/

# Copy Apache configuration file
COPY apache.conf /etc/apache2/sites-available/000-default.conf

# Enable Apache rewrite module
RUN a2enmod rewrite

# Install Docker Compose
RUN apt-get update && \
    apt-get install -y curl && \
    curl -sSL https://get.docker.com/ | sh && \
    curl -L https://github.com/docker/compose/releases/download/1.29.0/docker-compose-$(uname -s)-$(uname -m) -o /usr/local/bin/docker-compose && \
    chmod +x /usr/local/bin/docker-compose

# Set the working directory
WORKDIR /var/www/html

# Expose port 80
EXPOSE 80

# Start Apache server
CMD ["/usr/sbin/apache2ctl", "-D", "FOREGROUND"]

docker-compose.yml

version: '3.9'
services:

  db: 
    image: mysql:latest
    environment:
      - MYSQL_DATABASE=ehospital
      - MYSQL_USER=ehospital
      - MYSQL_PASSWORD=root
      - MYSQL_ALLOW_EMPTY_PASSWORD=1 
    volumes:
      - "./db:/docker-entrypoint-initdb.d" # persistent db 
      
  www:
    image: php:apache
    volumes:
      - "./:/var/www/html" 
    ports:
      - 80:80
      - 443:443 # for future ssl traffic

  phpmyadmin:
    image: phpmyadmin/phpmyadmin
    ports:
      - 8001:80
    environment:
      - PMA_HOST=db
      - PMA_PORT=3306
解决思路
  • 托管运行器的网络限制
    GitHub提供的ubuntu-latest托管运行器是临时虚拟机,你拿到的公网IP是平台NAT后的地址,运行器内部的端口不会暴露到公网。这是平台的网络隔离机制,目的是保障运行器安全性,所以没法直接通过这个IP访问内部容器服务。

  • 任务隔离的问题
    你的流水线里compose、prometheus、grafana是三个独立的job,每个job都会在全新的托管运行器实例上执行。也就是说,这三个job的容器分别跑在三个完全不同的虚拟机里,互相之间没有关联,自然没法通过同一个IP访问。

  • 正确的处理方向

    1. 不要用托管运行器对外提供服务:托管运行器是临时资源,任务结束后就会被销毁,不适合作为服务运行环境。应该把构建好的镜像部署到云服务器、K8s集群、Docker Swarm或者容器托管平台(比如AWS ECS、阿里云容器服务)。
    2. 内部验证服务状态:如果只是要验证容器是否能正常启动,可以把所有服务启动步骤放到同一个job里,然后在运行器内部用curl、wget访问localhost对应的端口,验证服务是否正常,而不是尝试从外部访问公网IP。
    3. 合并分散的job:把compose、prometheus、grafana的启动步骤合并到同一个job中,确保所有服务都运行在同一个运行器实例里,这样不仅能内部验证,服务之间也能正常通信。
  • 流水线配置优化示例
    调整后的job示例:

    deploy-and-verify:
      needs: build
      runs-on: ubuntu-latest
      steps:
        - name: Clone repository
          run: git clone https://github.com/sensgithub/eHospital.git
          working-directory: ${{ github.workspace }}
        
        - name: Start application services
          run: |
            cd eHospital
            docker-compose up -d
        
        - name: Start monitoring services
          run: |
            docker run -d --name prometheus -p 9090:9090 prom/prometheus
            docker run -d --name grafana -p 3000:3000 grafana/grafana
        
        - name: Wait for services to start
          run: sleep 30 # 根据服务启动时间调整
        
        - name: Verify services are running
          run: |
            curl -I http://localhost:80
            curl -I http://localhost:9090
            curl -I http://localhost:3000
    

内容的提问来源于stack exchange,提问作者sens31

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 18:24:59