You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Docker构建流程中实现私有Git仓库的身份验证

解决GitHub Actions构建容器时访问私有Git仓库的认证问题

我有一个私有Git仓库,在通过GitHub Workflow构建容器镜像并推送到ghcr.io时,因项目依赖的私有仓库无法访问导致构建失败。本地构建可正常运行,希望找到更优的私有仓库访问方案,而非修改GitHub认证存储方式。


现有GitHub Action配置

name: Docker dataeng_github_metrics

# Run workflow on tags starting with v (eg. v2, v1.2.0)
on:
  push:
    branches: [ "master" ]
    paths:
      - ./data_pipelines/dataeng_github_metrics/*
  pull_request:
    branches: [ "master" ]

jobs:
  Deploy:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout Code
        uses: actions/checkout@v1
        
      - name: Login to GitHub Container Registry
        uses: docker/login-action@v1
        with:
          registry: ghcr.io
          username: ${{ github.repository_owner }}
          password: ${{ secrets.GHCR_REGISTRY_TOKEN }}

      - name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v2

      - name: Build and Push Docker Image
        uses: docker/build-push-action@v3
        with:
          context: ./data_pipelines/dataeng_github_metrics/
          file: ./data_pipelines/dataeng_github_metrics/Dockerfile
          push: true # Will only build if this is not here
          tags: |
            ghcr.io/mirantis/dataeng_github_metrics:latest
          # TODO: I CANNOT USE DATAENG AS PUBLIC AND NEED TO CHANGE THE WAY GITCONFIG IS USED IN THE DOCKERFILE FOR AUTHENTICATION
          secrets: |
            TOKEN=${{ secrets.AUTOMATION_PAT}}

现有Dockerfile内容

###############
# CACHE IMAGE #
###############
ARG GO_IMAGE=golang:1.17.3-alpine3.14
ARG BASE_IMAGE=alpine:3.14.2

FROM ${GO_IMAGE} AS cache
# Add the keys
ARG GITHUB_ID
ENV GITHUB_ID=$GITHUB_ID
ARG GITHUB_TOKEN
ENV GITHUB_TOKEN=$GITHUB_TOKEN

# Install Git
RUN apk add git

# TODO: ENCRYPT THE GITHUB_ID AND GITHUB_TOKEN
# Make Git Configuration
RUN git config \
    --global \
    url."https://${GITHUB_ID}:${GITHUB_TOKEN}@github.com/".insteadOf \
    "https://github.com/"

WORKDIR /src
COPY go.mod go.sum /src/
RUN go mod download

##############
# BASE IMAGE #
##############
FROM cache AS dataeng_github_metrics
COPY . /bin
WORKDIR /bin

# Setup Git Terminal Prompt & Go Build
RUN go build .

###############
# FINAL IMAGE #
###############
FROM ${BASE_IMAGE}
COPY --from=dataeng_github_metrics /bin/dataeng_github_metrics bin/
ENTRYPOINT [ "bin/dataeng_github_metrics" ]

遇到的错误

#14 9.438   remote: Repository not found.
#14 9.438   fatal: Authentication failed for 'https://github.com/Mirantis/dataeng/'
------
Dockerfile:26
--------------------
  24 |     WORKDIR /src
  25 |     COPY go.mod go.sum /src/
  26 | >>> RUN go mod download
  27 |     
  28 |     ##############
--------------------
ERROR: failed to solve: process "/bin/sh -c go mod download" did not complete successfully: exit code: 1
Error: buildx failed with: ERROR: failed to solve: process "/bin/sh -c go mod download" did not complete successfully: exit code: 1

解决方案

方案一:使用BuildKit秘密传递(推荐)

利用Docker BuildKit的--secret功能安全传递认证信息,避免敏感数据残留到镜像中:

  1. 修改GitHub Action的构建步骤,传递所需秘密:
- name: Build and Push Docker Image
  uses: docker/build-push-action@v3
  with:
    context: ./data_pipelines/dataeng_github_metrics/
    file: ./data_pipelines/dataeng_github_metrics/Dockerfile
    push: true
    tags: |
      ghcr.io/mirantis/dataeng_github_metrics:latest
    secrets: |
      GITHUB_TOKEN=${{ secrets.AUTOMATION_PAT }}
      GITHUB_ID=${{ github.actor }} # 或指定你的GitHub用户名
  1. 更新Dockerfile的cache阶段,临时加载秘密并清理配置:
FROM ${GO_IMAGE} AS cache
# Install Git
RUN apk add git

# 临时加载秘密配置Git认证,构建后立即清理
RUN --mount=type=secret,id=GITHUB_ID \
    --mount=type=secret,id=GITHUB_TOKEN \
    GITHUB_ID=$(cat /run/secrets/GITHUB_ID) \
    GITHUB_TOKEN=$(cat /run/secrets/GITHUB_TOKEN) \
    git config --global url."https://${GITHUB_ID}:${GITHUB_TOKEN}@github.com/".insteadOf "https://github.com/"

WORKDIR /src
COPY go.mod go.sum /src/
RUN go mod download
# 彻底移除Git认证配置,避免敏感信息残留
RUN git config --global --unset url."https://github.com/".insteadOf

方案二:使用GitHub Actions内置GITHUB_TOKEN(无需额外PAT)

若私有依赖仓库与当前仓库同属一个组织,可直接使用Actions自动生成的GITHUB_TOKEN:

  1. 修改GitHub Action构建步骤:
- name: Build and Push Docker Image
  uses: docker/build-push-action@v3
  with:
    context: ./data_pipelines/dataeng_github_metrics/
    file: ./data_pipelines/dataeng_github_metrics/Dockerfile
    push: true
    tags: |
      ghcr.io/mirantis/dataeng_github_metrics:latest
    secrets: |
      GITHUB_TOKEN=${{ secrets.GITHUB_TOKEN }}
      GITHUB_ID=${{ github.actor }}
  1. 配置权限:
    • 进入当前仓库的Settings > Actions > General
    • 在Workflow permissions中选择Read and write permissions
    • 若依赖仓库为跨组织私有仓库,需在依赖仓库的权限设置中添加当前仓库的访问权限

方案三:快速修复现有配置(不推荐生产环境)

若暂时无法使用BuildKit秘密,可先修复参数传递问题,但此方式会将敏感信息嵌入镜像构建层:

  1. 修改GitHub Action,传递构建参数:
- name: Build and Push Docker Image
  uses: docker/build-push-action@v3
  with:
    context: ./data_pipelines/dataeng_github_metrics/
    file: ./data_pipelines/dataeng_github_metrics/Dockerfile
    push: true
    tags: |
      ghcr.io/mirantis/dataeng_github_metrics:latest
    build-args: |
      GITHUB_ID=${{ github.actor }}
      GITHUB_TOKEN=${{ secrets.AUTOMATION_PAT }}

内容的提问来源于stack exchange,提问作者R. Barrett

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 07:35:35