使用GitHub Actions部署Firebase Functions时无法识别项目的问题
解决GitHub Actions部署Firebase Functions时的项目激活问题
问题背景
我参考一篇Medium文章,使用GitHub Actions部署Firebase Functions,.github/workflows/firebase-deploy.yml的工作流配置如下:
name: Deploy Cloud Functions on: workflow_dispatch: push: branches: - master - pre-production - github-actions - "feature/**" paths: - "functions/**" jobs: build_and_deploy: runs-on: macos-latest steps: - uses: actions/checkout@v2 - uses: actions/setup-node@v1 with: node-version: 16.x - uses: actions/cache@v2 with: path: ~/.npm key: macOS-node-${{ hashFiles('**/functions/package-lock.json') }} restore-keys: | macOS-node- - name: Build Cloud Functions run: npm ci working-directory: functions - name: Create SA key run: echo '${{ secrets.FIREBASE_DEV_SERVICE_ACCOUNT }}' > gcloud.json working-directory: functions - name: Print json run: echo "$(cat gcloud.json)" working-directory: functions - name: Install firebase tools run: npm install -g firebase-tools working-directory: functions - name: Deploy Cloud Functions run: export GOOGLE_APPLICATION_CREDENTIALS=gcloud.json && npx firebase-tools deploy --only functions --json working-directory: functions
在GitHub Actions的「Deploy Cloud Functions」步骤中出现以下错误:
Run export GOOGLE_APPLICATION_CREDENTIALS=gcloud.json && npx firebase-tools deploy --only functions --json export GOOGLE_APPLICATION_CREDENTIALS=gcloud.json && npx firebase-tools deploy --only functions --json shell: /bin/bash -e ***0*** *** "status": "error", "error": "No project active, but project aliases are available.\n\nRun \u001b[1mfirebase use <alias>\u001b[22m with one of these options:\n\n dev (web3army-pre-prod)\n prod (blockchainarmy-6ed76)" *** Error: Process completed with exit code 1.
本地终端部署时,执行firebase use dev即可正常部署,且dev项目已在生成仓库密钥的Google服务账号JSON文件中指定。目前怀疑GOOGLE_APPLICATION_CREDENTIALS未与gcloud.json正确绑定,尝试打印JSON内容时被加密为***,无法排查具体问题。
修复方案
1. 直接在部署命令中指定项目ID
跳过别名依赖,直接在deploy命令里通过--project参数指定目标项目ID,比如你的dev项目ID是web3army-pre-prod,修改部署步骤命令:
export GOOGLE_APPLICATION_CREDENTIALS=gcloud.json && npx firebase-tools deploy --only functions --project web3army-pre-prod --json
2. 先激活项目再部署
利用服务账号认证后,先执行firebase use激活指定别名项目,再执行部署:
export GOOGLE_APPLICATION_CREDENTIALS=gcloud.json && npx firebase-tools use dev --token "$(gcloud auth print-access-token)" && npx firebase-tools deploy --only functions --json
或者直接从服务账号JSON中读取项目ID并指定:
export GOOGLE_APPLICATION_CREDENTIALS=gcloud.json && npx firebase-tools deploy --only functions --project $(jq -r .project_id gcloud.json) --json
注:如果环境没有jq工具,需要先在步骤中安装:brew install jq
3. 修复服务账号文件生成逻辑
生成gcloud.json时,单引号可能导致JSON字符串转义错误,修改生成步骤的命令:
- name: Create SA key run: echo "${{ secrets.FIREBASE_DEV_SERVICE_ACCOUNT }}" > gcloud.json working-directory: functions
4. 验证服务账号文件有效性
不要打印完整的敏感JSON内容,可通过以下步骤验证文件是否存在且格式正确:
- name: Validate SA key file run: | if [ -f gcloud.json ]; then echo "SA key file exists" jq . gcloud.json > /dev/null && echo "JSON format is valid" || echo "Invalid JSON" else echo "SA key file missing" fi working-directory: functions
内容的提问来源于stack exchange,提问作者Harry
相关产品推荐
相关产品推荐

