在GitHub Actions中无交互生成临时GPG密钥失败:目录权限问题导致无法连接GPG代理及Maven签名异常
Let's break down and fix the permission issues you're facing with GPG key generation and maven-gpg-plugin in your CI workflow. The core problem here is that GPG enforces strict directory permissions for its home directory, and your current setup isn't meeting those requirements.
Step 1: Fix the GPG Home Directory Permissions
Your error logs show "unsafe ownership" and "Permission denied" for the GNUPGHOME directory. GPG requires this directory to have 700 permissions (only the owner can read/write/execute) to ensure security. Here's how to adjust your key generation step:
- name: Generate transient GPG key run: > export GNUPGHOME="$(mktemp -d)" && chmod 700 "$GNUPGHOME" && cat >tempkey <<EOF %echo Generating a basic OpenPGP key Key-Type: DSA Key-Length: 1024 Subkey-Type: ELG-E Subkey-Length: 1024 Name-Real: J143 Bot Name-Comment: CI transient key Name-Email: j143+[bot]@protonmail.com Expire-Date: 0 Passphrase: ${{ secrets.GPG_PASSPHRASE }} %commit %echo done EOF gpg --batch --pinentry-mode loopback --generate-key tempkey
Key Changes Explained:
&&connects commands to ensure we only proceed if the previous step succeeds (no broken state if temp dir creation fails).chmod 700 "$GNUPGHOME"sets the strict permissions GPG requires, eliminating the "unsafe ownership" warning.--pinentry-mode loopbacktells GPG to use non-interactive password entry (critical for CI environments where no GUI is available).- Replaced hardcoded passphrase with a GitHub Secret (
${{ secrets.GPG_PASSPHRASE }}) for security—never commit credentials to your repo!
Step 2: Configure Maven-GPG-Plugin to Avoid Agent Issues
Your maven logs show useAgent = true, which is causing problems because the GPG agent can't start due to permission issues. Disable the agent and ensure Maven uses the correct GPG home directory:
Option 1: Update pom.xml Plugin Configuration
Add this to your maven-gpg-plugin setup:
<plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-gpg-plugin</artifactId> <version>1.6</version> <configuration> <homedir>${env.GNUPGHOME}</homedir> <passphraseServerId>gpg.passphrase</passphraseServerId> <useAgent>false</useAgent> <interactive>false</interactive> </configuration> </plugin>
Option 2: Pass Parameters Directly in GitHub Actions
If you prefer not to modify the pom.xml, pass the config as command-line arguments:
- name: Sign and deploy with Maven run: > mvn deploy -Dgpg.homedir="$GNUPGHOME" -Dgpg.passphrase=${{ secrets.GPG_PASSPHRASE }} -Dgpg.useAgent=false
Step 3: Verify the Workflow
After making these changes, your workflow should:
- Create a properly secured temporary GPG home directory.
- Generate the key without permission or agent errors.
- Use the generated key to sign your Maven artifacts successfully.
Additional Notes
- If you're using GPG 2.2+, you might also need to add
--no-ttyto the GPG command to suppress terminal-related warnings. - Ensure the GitHub Actions runner user owns the temporary directory (which
mktempshould handle by default, but thechmod 700step ensures permissions are locked down).
内容的提问来源于stack exchange,提问作者Janardhan

