You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在GitHub Actions中无交互生成临时GPG密钥失败:目录权限问题导致无法连接GPG代理及Maven签名异常

Fixing GPG Key Generation & Maven Signing Permissions in GitHub Actions

Let's break down and fix the permission issues you're facing with GPG key generation and maven-gpg-plugin in your CI workflow. The core problem here is that GPG enforces strict directory permissions for its home directory, and your current setup isn't meeting those requirements.

Step 1: Fix the GPG Home Directory Permissions

Your error logs show "unsafe ownership" and "Permission denied" for the GNUPGHOME directory. GPG requires this directory to have 700 permissions (only the owner can read/write/execute) to ensure security. Here's how to adjust your key generation step:

- name: Generate transient GPG key
  run: >
    export GNUPGHOME="$(mktemp -d)" &&
    chmod 700 "$GNUPGHOME" &&
    cat >tempkey <<EOF
    %echo Generating a basic OpenPGP key
    Key-Type: DSA
    Key-Length: 1024
    Subkey-Type: ELG-E
    Subkey-Length: 1024
    Name-Real: J143 Bot
    Name-Comment: CI transient key
    Name-Email: j143+[bot]@protonmail.com
    Expire-Date: 0
    Passphrase: ${{ secrets.GPG_PASSPHRASE }}
    %commit
    %echo done
    EOF
    gpg --batch --pinentry-mode loopback --generate-key tempkey

Key Changes Explained:

  • && connects commands to ensure we only proceed if the previous step succeeds (no broken state if temp dir creation fails).
  • chmod 700 "$GNUPGHOME" sets the strict permissions GPG requires, eliminating the "unsafe ownership" warning.
  • --pinentry-mode loopback tells GPG to use non-interactive password entry (critical for CI environments where no GUI is available).
  • Replaced hardcoded passphrase with a GitHub Secret (${{ secrets.GPG_PASSPHRASE }}) for security—never commit credentials to your repo!

Step 2: Configure Maven-GPG-Plugin to Avoid Agent Issues

Your maven logs show useAgent = true, which is causing problems because the GPG agent can't start due to permission issues. Disable the agent and ensure Maven uses the correct GPG home directory:

Option 1: Update pom.xml Plugin Configuration

Add this to your maven-gpg-plugin setup:

<plugin>
  <groupId>org.apache.maven.plugins</groupId>
  <artifactId>maven-gpg-plugin</artifactId>
  <version>1.6</version>
  <configuration>
    <homedir>${env.GNUPGHOME}</homedir>
    <passphraseServerId>gpg.passphrase</passphraseServerId>
    <useAgent>false</useAgent>
    <interactive>false</interactive>
  </configuration>
</plugin>

Option 2: Pass Parameters Directly in GitHub Actions

If you prefer not to modify the pom.xml, pass the config as command-line arguments:

- name: Sign and deploy with Maven
  run: >
    mvn deploy 
    -Dgpg.homedir="$GNUPGHOME" 
    -Dgpg.passphrase=${{ secrets.GPG_PASSPHRASE }} 
    -Dgpg.useAgent=false

Step 3: Verify the Workflow

After making these changes, your workflow should:

  1. Create a properly secured temporary GPG home directory.
  2. Generate the key without permission or agent errors.
  3. Use the generated key to sign your Maven artifacts successfully.

Additional Notes

  • If you're using GPG 2.2+, you might also need to add --no-tty to the GPG command to suppress terminal-related warnings.
  • Ensure the GitHub Actions runner user owns the temporary directory (which mktemp should handle by default, but the chmod 700 step ensures permissions are locked down).

内容的提问来源于stack exchange,提问作者Janardhan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.01 02:07:31