如何在Docker构建流程中实现私有Git仓库的身份验证
解决GitHub Actions构建容器时访问私有Git仓库的认证问题
我有一个私有Git仓库,在通过GitHub Workflow构建容器镜像并推送到ghcr.io时,因项目依赖的私有仓库无法访问导致构建失败。本地构建可正常运行,希望找到更优的私有仓库访问方案,而非修改GitHub认证存储方式。
现有GitHub Action配置
name: Docker dataeng_github_metrics # Run workflow on tags starting with v (eg. v2, v1.2.0) on: push: branches: [ "master" ] paths: - ./data_pipelines/dataeng_github_metrics/* pull_request: branches: [ "master" ] jobs: Deploy: runs-on: ubuntu-latest steps: - name: Checkout Code uses: actions/checkout@v1 - name: Login to GitHub Container Registry uses: docker/login-action@v1 with: registry: ghcr.io username: ${{ github.repository_owner }} password: ${{ secrets.GHCR_REGISTRY_TOKEN }} - name: Set up Docker Buildx uses: docker/setup-buildx-action@v2 - name: Build and Push Docker Image uses: docker/build-push-action@v3 with: context: ./data_pipelines/dataeng_github_metrics/ file: ./data_pipelines/dataeng_github_metrics/Dockerfile push: true # Will only build if this is not here tags: | ghcr.io/mirantis/dataeng_github_metrics:latest # TODO: I CANNOT USE DATAENG AS PUBLIC AND NEED TO CHANGE THE WAY GITCONFIG IS USED IN THE DOCKERFILE FOR AUTHENTICATION secrets: | TOKEN=${{ secrets.AUTOMATION_PAT}}
现有Dockerfile内容
############### # CACHE IMAGE # ############### ARG GO_IMAGE=golang:1.17.3-alpine3.14 ARG BASE_IMAGE=alpine:3.14.2 FROM ${GO_IMAGE} AS cache # Add the keys ARG GITHUB_ID ENV GITHUB_ID=$GITHUB_ID ARG GITHUB_TOKEN ENV GITHUB_TOKEN=$GITHUB_TOKEN # Install Git RUN apk add git # TODO: ENCRYPT THE GITHUB_ID AND GITHUB_TOKEN # Make Git Configuration RUN git config \ --global \ url."https://${GITHUB_ID}:${GITHUB_TOKEN}@github.com/".insteadOf \ "https://github.com/" WORKDIR /src COPY go.mod go.sum /src/ RUN go mod download ############## # BASE IMAGE # ############## FROM cache AS dataeng_github_metrics COPY . /bin WORKDIR /bin # Setup Git Terminal Prompt & Go Build RUN go build . ############### # FINAL IMAGE # ############### FROM ${BASE_IMAGE} COPY --from=dataeng_github_metrics /bin/dataeng_github_metrics bin/ ENTRYPOINT [ "bin/dataeng_github_metrics" ]
遇到的错误
#14 9.438 remote: Repository not found. #14 9.438 fatal: Authentication failed for 'https://github.com/Mirantis/dataeng/' ------ Dockerfile:26 -------------------- 24 | WORKDIR /src 25 | COPY go.mod go.sum /src/ 26 | >>> RUN go mod download 27 | 28 | ############## -------------------- ERROR: failed to solve: process "/bin/sh -c go mod download" did not complete successfully: exit code: 1 Error: buildx failed with: ERROR: failed to solve: process "/bin/sh -c go mod download" did not complete successfully: exit code: 1
解决方案
方案一:使用BuildKit秘密传递(推荐)
利用Docker BuildKit的--secret功能安全传递认证信息,避免敏感数据残留到镜像中:
- 修改GitHub Action的构建步骤,传递所需秘密:
- name: Build and Push Docker Image uses: docker/build-push-action@v3 with: context: ./data_pipelines/dataeng_github_metrics/ file: ./data_pipelines/dataeng_github_metrics/Dockerfile push: true tags: | ghcr.io/mirantis/dataeng_github_metrics:latest secrets: | GITHUB_TOKEN=${{ secrets.AUTOMATION_PAT }} GITHUB_ID=${{ github.actor }} # 或指定你的GitHub用户名
- 更新Dockerfile的
cache阶段,临时加载秘密并清理配置:
FROM ${GO_IMAGE} AS cache # Install Git RUN apk add git # 临时加载秘密配置Git认证,构建后立即清理 RUN --mount=type=secret,id=GITHUB_ID \ --mount=type=secret,id=GITHUB_TOKEN \ GITHUB_ID=$(cat /run/secrets/GITHUB_ID) \ GITHUB_TOKEN=$(cat /run/secrets/GITHUB_TOKEN) \ git config --global url."https://${GITHUB_ID}:${GITHUB_TOKEN}@github.com/".insteadOf "https://github.com/" WORKDIR /src COPY go.mod go.sum /src/ RUN go mod download # 彻底移除Git认证配置,避免敏感信息残留 RUN git config --global --unset url."https://github.com/".insteadOf
方案二:使用GitHub Actions内置GITHUB_TOKEN(无需额外PAT)
若私有依赖仓库与当前仓库同属一个组织,可直接使用Actions自动生成的GITHUB_TOKEN:
- 修改GitHub Action构建步骤:
- name: Build and Push Docker Image uses: docker/build-push-action@v3 with: context: ./data_pipelines/dataeng_github_metrics/ file: ./data_pipelines/dataeng_github_metrics/Dockerfile push: true tags: | ghcr.io/mirantis/dataeng_github_metrics:latest secrets: | GITHUB_TOKEN=${{ secrets.GITHUB_TOKEN }} GITHUB_ID=${{ github.actor }}
- 配置权限:
- 进入当前仓库的
Settings > Actions > General - 在
Workflow permissions中选择Read and write permissions - 若依赖仓库为跨组织私有仓库,需在依赖仓库的权限设置中添加当前仓库的访问权限
- 进入当前仓库的
方案三:快速修复现有配置(不推荐生产环境)
若暂时无法使用BuildKit秘密,可先修复参数传递问题,但此方式会将敏感信息嵌入镜像构建层:
- 修改GitHub Action,传递构建参数:
- name: Build and Push Docker Image uses: docker/build-push-action@v3 with: context: ./data_pipelines/dataeng_github_metrics/ file: ./data_pipelines/dataeng_github_metrics/Dockerfile push: true tags: | ghcr.io/mirantis/dataeng_github_metrics:latest build-args: | GITHUB_ID=${{ github.actor }} GITHUB_TOKEN=${{ secrets.AUTOMATION_PAT }}
内容的提问来源于stack exchange,提问作者R. Barrett
相关产品推荐
相关产品推荐

