私有仓库间调用Composite GitHub Action执行Python脚本遇权限问题
问题描述
我希望将一个Python脚本作为多个私有仓库的最终部署步骤执行,由于该脚本调用GitHub API,我将其逻辑封装为独立的GitHub Action(对应私有仓库org/my-action),并已配置该仓库允许组织内私有仓库访问。另一私有仓库org/core需调用此Action,但遇到以下问题:
- 初始
action.yml中使用actions/checkout@v3会检出org/core仓库,导致依赖安装和脚本执行错误。 - 修改
action.yml指定检出org/my-action后,出现Error: fatal: repository 'https://github.com/org/my-action' not found的错误。
不想通过创建PAT密钥解决,寻求更优雅的实现方式。
解决方案1:利用默认GITHUB_TOKEN完成私有仓库检出
组织内已配置仓库访问权限的前提下,直接在checkout步骤中使用工作流默认的GITHUB_TOKEN即可,无需额外创建PAT。修改org/my-action的action.yml如下:
name: Release to Calendar inputs: calendar-id: description: 'Unique identifier' required: true runs: using: "composite" steps: - uses: actions/checkout@v3 with: repository: 'org/my-action' ref: 'main' path: 'calendar-action' token: ${{ github.token }} # 核心:使用工作流默认token - uses: actions/setup-python@v4 with: python-version: '3.11' - name: Install dependencies shell: "bash" run: pip install -r calendar-action/requirements.txt - name: Create calendar event shell: "bash" run: python calendar-action/main.py ${{ inputs.calendar-id }}
原理:工作流默认的GITHUB_TOKEN拥有当前执行仓库(org/core)的权限,而你已配置org/my-action允许组织内私有仓库访问,因此该token可正常拉取org/my-action的代码。
解决方案2:改用Docker容器型Action(更简洁高效)
将Python脚本和依赖预打包为Docker镜像,彻底规避代码检出的权限问题,同时提升Action执行效率。
1. 在org/my-action中添加Dockerfile
FROM python:3.11-slim WORKDIR /action COPY requirements.txt . RUN pip install --no-cache-dir -r requirements.txt COPY main.py . ENTRYPOINT ["python", "/action/main.py"]
2. 修改org/my-action的action.yml为容器类型
name: Release to Calendar inputs: calendar-id: description: 'Unique identifier' required: true runs: using: "docker" image: "Dockerfile" args: - ${{ inputs.calendar-id }}
3. org/core的调用工作流保持不变
name: release to calendar on: workflow_dispatch jobs: to-calendar: runs-on: ubuntu-latest steps: - uses: org/my-action@main with: calendar-id: 'some value'
优势:
- GitHub Actions会自动处理私有仓库的Docker镜像拉取(依赖组织内权限配置),无需手动处理权限。
- 依赖预打包在镜像中,避免每次执行重复安装,执行速度更快。
内容的提问来源于stack exchange,提问作者Gustavo Puma
相关产品推荐
相关产品推荐

