Github Actions部署Azure失败:Az CLI登录及工作目录报错求助
问题背景
作为GitHub Actions新手,现有一个部署应用到Azure的流水线,包含3个任务,前两个任务执行成功,但最后部署阶段持续失败。
初始错误
Az CLI Login failed. Please check the credentials and make sure az is installed on the runner. For more information refer https://aka.ms/create-secrets-for-GitHub-workflows
初始部署任务配置
name: myapp env: AZURE_WEBAPP_PACKAGE_PATH: '.' DOTNET_VERSION: '6.0.x' # set this to the .NET Core version to use on: push: branches: [ "master" ] workflow_dispatch: defaults: run: working-directory: app/myapp permissions: contents: read deploy: defaults: run: working-directory: app/myapp permissions: contents: none runs-on: ubuntu-latest needs: [build,access] if: needs.access.outputs.secrets-valid == 'true' environment: name: 'Test-QA' url: ${{ steps.deploy-to-webapp.outputs.webapp-url }} steps: - name: Download artifact from build job uses: actions/download-artifact@v3 with: name: .net-app - name: Login to Azure uses: azure/login@v1 with: creds: ${{ secrets.AZURE_CREDENTIALS }} enable-AzPSSession: true - name: Deploy to Azure Web App id: deploy-to-webapp uses: azure/webapps-deploy@v2 with: app-name: ${{ secrets.AZURE_WEBAPP_NAME }} publish-profile: ${{ secrets.AZURE_WEBAPP_PUBLISH_PROFILE }} package: ${{ env.AZURE_WEBAPP_PACKAGE_PATH }}
修改后的尝试及新错误
尝试在登录步骤前安装Azure CLI,修改后的步骤如下:
steps: - name: Download artifact from build job uses: actions/download-artifact@v3 with: name: .net-app - name: Install Azure cli run: | sudo apt-get install ca-certificates curl apt-transport-https lsb-release gnupg curl -sL https://packages.microsoft.com/keys/microsoft.asc | gpg --dearmor | sudo tee /etc/apt/trusted.gpg.d/microsoft.gpg > /dev/null AZ_REPO=$(lsb_release -cs) echo "deb [arch=amd64] https://packages.microsoft.com/repos/azure-cli/ $AZ_REPO main" | sudo tee /etc/apt/sources.list.d/azure-cli.list sudo apt-get update sudo apt-get install azure-cli - name: Login to Azure uses: azure/login@v1 with: creds: ${{ secrets.AZURE_CREDENTIALS }} enable-AzPSSession: true - name: Deploy to Azure Web App id: deploy-to-webapp uses: azure/webapps-deploy@v2 with: app-name: ${{ secrets.AZURE_WEBAPP_NAME }} publish-profile: ${{ secrets.AZURE_WEBAPP_PUBLISH_PROFILE }} package: ${{ env.AZURE_WEBAPP_PACKAGE_PATH }}
修改后出现新错误:
Error: An error occurred trying to start process '/usr/bin/bash' with working directory '/runner/_work/...dir/app/myapp'. No such file or directory
问题分析与解决步骤
1. 核心问题定位
新错误提示的工作目录不存在,原因是:
deploy任务设置了默认工作目录为app/myapp,但下载工件后该目录在runner环境中未创建;actions/download-artifact不会自动创建目标目录,后续run步骤因找不到目录报错。
2. 分步解决
步骤一:移除不必要的Azure CLI安装
GitHub托管的ubuntu-latest runner默认预装了Azure CLI,手动安装完全多余,直接删除该步骤即可。
步骤二:修复工作目录问题
提供两种可行方案:
方案A:确保工作目录存在
在下载工件前先创建指定目录,同时明确工件下载路径:deploy: permissions: contents: none runs-on: ubuntu-latest needs: [build,access] if: needs.access.outputs.secrets-valid == 'true' environment: name: 'Test-QA' url: ${{ steps.deploy-to-webapp.outputs.webapp-url }} steps: - name: Create working directory run: mkdir -p app/myapp working-directory: ${{ github.workspace }} - name: Download artifact from build job uses: actions/download-artifact@v3 with: name: .net-app path: app/myapp - name: Login to Azure uses: azure/login@v1 with: creds: ${{ secrets.AZURE_CREDENTIALS }} - name: Deploy to Azure Web App id: deploy-to-webapp uses: azure/webapps-deploy@v2 with: app-name: ${{ secrets.AZURE_WEBAPP_NAME }} publish-profile: ${{ secrets.AZURE_WEBAPP_PUBLISH_PROFILE }} package: app/myapp方案B:取消任务级默认工作目录
删除deploy任务中的默认工作目录配置,调整包路径为工件实际下载位置:env: AZURE_WEBAPP_PACKAGE_PATH: './.net-app' # ... 其他配置保持不变 ... deploy: permissions: contents: none runs-on: ubuntu-latest needs: [build,access] if: needs.access.outputs.secrets-valid == 'true' environment: name: 'Test-QA' url: ${{ steps.deploy-to-webapp.outputs.webapp-url }} steps: - name: Download artifact from build job uses: actions/download-artifact@v3 with: name: .net-app - name: Login to Azure uses: azure/login@v1 with: creds: ${{ secrets.AZURE_CREDENTIALS }} - name: Deploy to Azure Web App id: deploy-to-webapp uses: azure/webapps-deploy@v2 with: app-name: ${{ secrets.AZURE_WEBAPP_NAME }} publish-profile: ${{ secrets.AZURE_WEBAPP_PUBLISH_PROFILE }} package: ${{ env.AZURE_WEBAPP_PACKAGE_PATH }}
步骤三:简化部署流程(可选)
如果使用AZURE_WEBAPP_PUBLISH_PROFILE,可以直接跳过azure/login步骤,azure/webapps-deploy支持直接用发布配置文件部署:
- name: Deploy to Azure Web App id: deploy-to-webapp uses: azure/webapps-deploy@v2 with: app-name: ${{ secrets.AZURE_WEBAPP_NAME }} publish-profile: ${{ secrets.AZURE_WEBAPP_PUBLISH_PROFILE }} package: ${{ env.AZURE_WEBAPP_PACKAGE_PATH }}
3. 验证凭证有效性
回到初始登录错误,需确认:
AZURE_CREDENTIALS是包含clientId、clientSecret、subscriptionId、tenantId的合法JSON字符串;- 凭证对应的Azure账号拥有目标Web App的部署权限。
内容的提问来源于stack exchange,提问作者Godwin

