You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub自托管Runner:Ubuntu实例无法获取OIDC令牌问题

自托管Runner通过OIDC获取AWS角色令牌失败排查(Ubuntu)

问题场景

我在两台设备部署了GitHub自托管Runner:Macbook Pro与Ubuntu桌面。Macbook Pro上的Runner运行正常,但Ubuntu上的Runner执行AWS OIDC角色获取步骤时失败,报错信息如下:

Error: The security token included in the request is invalid.

失败的工作流步骤:

- name: Assume role using OIDC
  uses: aws-actions/configure-aws-credentials@master
  with:
    role-to-assume: arn:aws:iam::123456789012:role/github-connection-role
    aws-region: us-west-2

完整工作流配置:

name: Deploy
on:
  push:
    branches:
      - main

jobs:
  ci:
    name: Build and deploy with Node 16
    timeout-minutes: 60
    runs-on: self-hosted

    permissions:
      id-token: write
      contents: read

    steps:
      - name: Checkout
        uses: actions/checkout@v3

      - name: Use Node.js 16
        uses: actions/setup-node@v3
        with:
          node-version: 16
          cache: 'npm'
          cache-dependency-path: package-lock.json

      - name: Install dependencies
        run: npm install

      - name: Build
        run: npm run build

      - name: Assume role using OIDC
        uses: aws-actions/configure-aws-credentials@master
        with:
          role-to-assume: arn:aws:iam::123456789012:role/github-connection-role
          aws-region: us-west-2

      - name: Deploy
        run: npx cdk deploy app-production-stack --ci --require-approval never

排查与解决要点

  • 无需在Runner主机额外配置令牌相关内容:自托管Runner的作业获取GitHub OIDC令牌是由GitHub Actions服务自动注入环境变量实现的,不需要在Ubuntu主机上手动配置密钥或令牌,Mac端的正常运行也验证了这一点。
  • 检查Ubuntu Runner的网络环境:
    • 确认Ubuntu主机能正常访问https://token.actions.githubusercontent.com(GitHub OIDC端点)和AWS STS服务,排查防火墙、代理或DNS解析是否拦截了请求。
    • 如果主机使用代理,需确保Runner进程已配置正确的HTTP_PROXY、HTTPS_PROXY环境变量,否则令牌获取请求会失败。
  • 验证AWS IAM角色信任策略:
    • 确认角色的信任策略已正确关联GitHub OIDC提供商,且条件匹配当前工作流的上下文(仓库名、分支名)。示例信任策略:
      {
        "Version": "2012-10-17",
        "Statement": [
          {
            "Effect": "Allow",
            "Principal": {
              "Federated": "arn:aws:iam::123456789012:oidc-provider/token.actions.githubusercontent.com"
            },
            "Action": "sts:AssumeRoleWithWebIdentity",
            "Condition": {
              "StringEquals": {
                "token.actions.githubusercontent.com:aud": "sts.amazonaws.com",
                "token.actions.githubusercontent.com:sub": "repo:<你的用户名>/<你的仓库名>:ref:refs/heads/main"
              }
            }
          }
        ]
      }
      
    • 注意sub字段必须精确匹配触发工作流的仓库和分支,避免拼写错误导致令牌验证失败。
  • 检查Runner的运行权限:
    • 确保Ubuntu上的Runner以普通用户运行(而非root),部分环境下root用户可能影响环境变量的正常注入。
    • 确认Runner安装目录的权限正确,作业能读取GitHub注入的ACTIONS_ID_TOKEN_REQUEST_URL、ACTIONS_ID_TOKEN_REQUEST_TOKEN等环境变量。
  • 固定AWS Action版本:当前使用master分支存在兼容性风险,建议更换为稳定固定版本,修改后的步骤:
    - name: Assume role using OIDC
      uses: aws-actions/configure-aws-credentials@v4
      with:
        role-to-assume: arn:aws:iam::123456789012:role/github-connection-role
        aws-region: us-west-2
    

内容的提问来源于stack exchange,提问作者SimpleJ

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 22:57:43