如何在可复用GitHub Actions工作流中正确使用密钥?
问题核心分析
你遇到的所有错误,本质是混淆了GitHub Actions中「可复用工作流」和「自定义Action」的语法规则:
- 你按「可复用工作流」的语法(使用
on: workflow_call)定义了登录逻辑,但调用时却用了自定义Action的uses: ./.github/actions/xxx语法,两者的复用规则完全不同。 - 可复用工作流是完整的工作流单元,需放在
.github/workflows/目录下;自定义Action是嵌入现有Job的步骤集合,需放在.github/actions/目录下并通过action.yml定义。
解决方案一:改为正确的可复用工作流
适合将登录作为独立Job复用的场景:
1. 调整文件位置
将你的登录工作流文件从.github/actions/log-into-azure/action.yml移动到.github/workflows/log-into-azure.yml。
2. 可复用工作流代码(保持原有逻辑)
name: Log into Azure description: 'Log into Azure.' on: workflow_call: secrets: DEV_APPLICATION_ID: required: true DEV_SERVICE_PRINCIPAL_SECRET: required: true TENANT_ID: required: true jobs: azure-login: runs-on: [self-hosted, ubuntu-latest] steps: - name: Azure login with elevated permissions shell: pwsh run: | az login --service-principal -u "${{ secrets.DEV_APPLICATION_ID }}" -p "${{ secrets.DEV_SERVICE_PRINCIPAL_SECRET }}" --tenant "${{ secrets.TENANT_ID }}"
3. 调用工作流的正确写法
在调用方的工作流中,将可复用工作流作为独立Job引用,而非放在steps内:
name: Deploy to persistent environment on: workflow_dispatch: jobs: # 调用可复用登录工作流作为独立Job azure-login: uses: ./.github/workflows/log-into-azure.yml secrets: DEV_APPLICATION_ID: ${{ secrets.DEV_APPLICATION_ID }} DEV_SERVICE_PRINCIPAL_SECRET: ${{ secrets.DEV_SERVICE_PRINCIPAL_SECRET }} TENANT_ID: ${{ secrets.TENANT_ID }} # 部署Job依赖登录Job完成 deploy-kms-to-persistent-environment: name: 'Deploy KMS to ${{ github.event.inputs.deployment_target}} from Git commit: ${{ github.sha }}' runs-on: [self-hosted, 3shape-ubuntu-latest] needs: azure-login steps: # 在此添加你的部署步骤
如果调用方的Secrets名称与可复用工作流完全一致,可简化为:
jobs: azure-login: uses: ./.github/workflows/log-into-azure.yml secrets: inherit
解决方案二:改为自定义Action
适合将登录逻辑嵌入现有Job的Steps中的场景:
1. 自定义Action的action.yml配置
修改.github/actions/log-into-azure/action.yml,用secrets字段定义敏感参数(而非on: workflow_call):
name: Log into Azure description: 'Log into Azure.' secrets: DEV_APPLICATION_ID: required: true DEV_SERVICE_PRINCIPAL_SECRET: required: true TENANT_ID: required: true runs: using: 'composite' steps: - name: Azure login with elevated permissions shell: pwsh run: | az login --service-principal -u "${{ secrets.DEV_APPLICATION_ID }}" -p "${{ secrets.DEV_SERVICE_PRINCIPAL_SECRET }}" --tenant "${{ secrets.TENANT_ID }}"
2. 调用自定义Action的正确写法
在调用方的Steps中直接引用,通过secrets字段传递敏感信息:
name: Deploy to persistent environment on: workflow_dispatch: jobs: deploy-kms-to-persistent-environment: name: 'Deploy KMS to ${{ github.event.inputs.deployment_target}} from Git commit: ${{ github.sha }}' runs-on: [self-hosted, 3shape-ubuntu-latest] steps: - name: Azure login with elevated permissions uses: ./.github/actions/log-into-azure secrets: DEV_APPLICATION_ID: ${{ secrets.DEV_APPLICATION_ID }} DEV_SERVICE_PRINCIPAL_SECRET: ${{ secrets.DEV_SERVICE_PRINCIPAL_SECRET }} TENANT_ID: ${{ secrets.TENANT_ID }} # 后续添加部署步骤
关键规则总结
| 类型 | 文件位置 | 定义语法核心 | 调用方式 |
|---|---|---|---|
| 可复用工作流 | .github/workflows/ | on: workflow_call | 作为独立Job添加到jobs列表 |
| 自定义Action | .github/actions/ | secrets/inputs | 嵌入现有Job的steps中 |
内容的提问来源于stack exchange,提问作者Claus Appel
相关产品推荐
相关产品推荐

