GitHub自托管Runner:Ubuntu实例无法获取OIDC令牌问题
自托管Runner通过OIDC获取AWS角色令牌失败排查(Ubuntu)
问题场景
我在两台设备部署了GitHub自托管Runner:Macbook Pro与Ubuntu桌面。Macbook Pro上的Runner运行正常,但Ubuntu上的Runner执行AWS OIDC角色获取步骤时失败,报错信息如下:
Error: The security token included in the request is invalid.
失败的工作流步骤:
- name: Assume role using OIDC uses: aws-actions/configure-aws-credentials@master with: role-to-assume: arn:aws:iam::123456789012:role/github-connection-role aws-region: us-west-2
完整工作流配置:
name: Deploy on: push: branches: - main jobs: ci: name: Build and deploy with Node 16 timeout-minutes: 60 runs-on: self-hosted permissions: id-token: write contents: read steps: - name: Checkout uses: actions/checkout@v3 - name: Use Node.js 16 uses: actions/setup-node@v3 with: node-version: 16 cache: 'npm' cache-dependency-path: package-lock.json - name: Install dependencies run: npm install - name: Build run: npm run build - name: Assume role using OIDC uses: aws-actions/configure-aws-credentials@master with: role-to-assume: arn:aws:iam::123456789012:role/github-connection-role aws-region: us-west-2 - name: Deploy run: npx cdk deploy app-production-stack --ci --require-approval never
排查与解决要点
- 无需在Runner主机额外配置令牌相关内容:自托管Runner的作业获取GitHub OIDC令牌是由GitHub Actions服务自动注入环境变量实现的,不需要在Ubuntu主机上手动配置密钥或令牌,Mac端的正常运行也验证了这一点。
- 检查Ubuntu Runner的网络环境:
- 确认Ubuntu主机能正常访问
https://token.actions.githubusercontent.com(GitHub OIDC端点)和AWS STS服务,排查防火墙、代理或DNS解析是否拦截了请求。 - 如果主机使用代理,需确保Runner进程已配置正确的
HTTP_PROXY、HTTPS_PROXY环境变量,否则令牌获取请求会失败。
- 确认Ubuntu主机能正常访问
- 验证AWS IAM角色信任策略:
- 确认角色的信任策略已正确关联GitHub OIDC提供商,且条件匹配当前工作流的上下文(仓库名、分支名)。示例信任策略:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Federated": "arn:aws:iam::123456789012:oidc-provider/token.actions.githubusercontent.com" }, "Action": "sts:AssumeRoleWithWebIdentity", "Condition": { "StringEquals": { "token.actions.githubusercontent.com:aud": "sts.amazonaws.com", "token.actions.githubusercontent.com:sub": "repo:<你的用户名>/<你的仓库名>:ref:refs/heads/main" } } } ] } - 注意
sub字段必须精确匹配触发工作流的仓库和分支,避免拼写错误导致令牌验证失败。
- 确认角色的信任策略已正确关联GitHub OIDC提供商,且条件匹配当前工作流的上下文(仓库名、分支名)。示例信任策略:
- 检查Runner的运行权限:
- 确保Ubuntu上的Runner以普通用户运行(而非root),部分环境下root用户可能影响环境变量的正常注入。
- 确认Runner安装目录的权限正确,作业能读取GitHub注入的
ACTIONS_ID_TOKEN_REQUEST_URL、ACTIONS_ID_TOKEN_REQUEST_TOKEN等环境变量。
- 固定AWS Action版本:当前使用
master分支存在兼容性风险,建议更换为稳定固定版本,修改后的步骤:- name: Assume role using OIDC uses: aws-actions/configure-aws-credentials@v4 with: role-to-assume: arn:aws:iam::123456789012:role/github-connection-role aws-region: us-west-2
内容的提问来源于stack exchange,提问作者SimpleJ
相关产品推荐
相关产品推荐

