You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在可复用GitHub Actions工作流中正确使用密钥?

问题核心分析

你遇到的所有错误,本质是混淆了GitHub Actions中「可复用工作流」和「自定义Action」的语法规则:

  • 你按「可复用工作流」的语法(使用on: workflow_call)定义了登录逻辑,但调用时却用了自定义Action的uses: ./.github/actions/xxx语法,两者的复用规则完全不同。
  • 可复用工作流是完整的工作流单元,需放在.github/workflows/目录下;自定义Action是嵌入现有Job的步骤集合,需放在.github/actions/目录下并通过action.yml定义。

解决方案一:改为正确的可复用工作流

适合将登录作为独立Job复用的场景:

1. 调整文件位置

将你的登录工作流文件从.github/actions/log-into-azure/action.yml移动到.github/workflows/log-into-azure.yml。

2. 可复用工作流代码(保持原有逻辑)

name: Log into Azure
description: 'Log into Azure.'

on:
  workflow_call:
    secrets:
      DEV_APPLICATION_ID:
        required: true
      DEV_SERVICE_PRINCIPAL_SECRET:
        required: true
      TENANT_ID:
        required: true

jobs:
  azure-login:
    runs-on: [self-hosted, ubuntu-latest]
    steps:
      - name: Azure login with elevated permissions
        shell: pwsh
        run: |
          az login --service-principal -u "${{ secrets.DEV_APPLICATION_ID }}" -p "${{ secrets.DEV_SERVICE_PRINCIPAL_SECRET }}" --tenant "${{ secrets.TENANT_ID }}"

3. 调用工作流的正确写法

在调用方的工作流中,将可复用工作流作为独立Job引用,而非放在steps内:

name: Deploy to persistent environment

on:
  workflow_dispatch:

jobs:
  # 调用可复用登录工作流作为独立Job
  azure-login:
    uses: ./.github/workflows/log-into-azure.yml
    secrets:
      DEV_APPLICATION_ID: ${{ secrets.DEV_APPLICATION_ID }}
      DEV_SERVICE_PRINCIPAL_SECRET: ${{ secrets.DEV_SERVICE_PRINCIPAL_SECRET }}
      TENANT_ID: ${{ secrets.TENANT_ID }}

  # 部署Job依赖登录Job完成
  deploy-kms-to-persistent-environment:
    name: 'Deploy KMS to ${{ github.event.inputs.deployment_target}} from Git commit: ${{ github.sha }}'
    runs-on: [self-hosted, 3shape-ubuntu-latest]
    needs: azure-login
    steps:
      # 在此添加你的部署步骤

如果调用方的Secrets名称与可复用工作流完全一致,可简化为:

jobs:
  azure-login:
    uses: ./.github/workflows/log-into-azure.yml
    secrets: inherit

解决方案二:改为自定义Action

适合将登录逻辑嵌入现有Job的Steps中的场景:

1. 自定义Action的action.yml配置

修改.github/actions/log-into-azure/action.yml,用secrets字段定义敏感参数(而非on: workflow_call):

name: Log into Azure
description: 'Log into Azure.'

secrets:
  DEV_APPLICATION_ID:
    required: true
  DEV_SERVICE_PRINCIPAL_SECRET:
    required: true
  TENANT_ID:
    required: true

runs:
  using: 'composite'
  steps:
    - name: Azure login with elevated permissions
      shell: pwsh
      run: |
        az login --service-principal -u "${{ secrets.DEV_APPLICATION_ID }}" -p "${{ secrets.DEV_SERVICE_PRINCIPAL_SECRET }}" --tenant "${{ secrets.TENANT_ID }}"

2. 调用自定义Action的正确写法

在调用方的Steps中直接引用,通过secrets字段传递敏感信息:

name: Deploy to persistent environment

on:
  workflow_dispatch:

jobs:
  deploy-kms-to-persistent-environment:
    name: 'Deploy KMS to ${{ github.event.inputs.deployment_target}} from Git commit: ${{ github.sha }}'
    runs-on: [self-hosted, 3shape-ubuntu-latest]

    steps:
    - name: Azure login with elevated permissions
      uses: ./.github/actions/log-into-azure
      secrets:
        DEV_APPLICATION_ID: ${{ secrets.DEV_APPLICATION_ID }}
        DEV_SERVICE_PRINCIPAL_SECRET: ${{ secrets.DEV_SERVICE_PRINCIPAL_SECRET }}
        TENANT_ID: ${{ secrets.TENANT_ID }}
    
    # 后续添加部署步骤

关键规则总结

类型文件位置定义语法核心调用方式
可复用工作流.github/workflows/on: workflow_call作为独立Job添加到jobs列表
自定义Action.github/actions/secrets/inputs嵌入现有Job的steps中

内容的提问来源于stack exchange,提问作者Claus Appel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 18:10:29