如何在GitHub Actions中运行用GitHub Secrets替代输入的zx脚本?
可以在GitHub Actions中运行该脚本并使用GitHub Secrets替代手动输入token
完全可以实现,只需要对脚本和GitHub Actions工作流做两处关键调整:
1. 修改zx脚本,从环境变量获取token
把原来通过交互式提问获取token的逻辑,改成读取环境变量。这样GitHub Secrets注入的token就能被脚本直接使用,同时增加token存在性校验,避免脚本无意义执行:
#!/usr/bin/env zx const ENV_LIST = fs .readdirSync('apps') .filter(dir => !dir.endsWith('e2e') && !dir.startsWith('.')); const GLOBAL_ENV_DIR = path.join(__dirname, '../../../../.env'); const getAppEnvDir = appName => path.join(__dirname, `../../../../apps/${appName}/.env`); // 从环境变量读取token,替代交互式提问 const token = process.env.TEAM_API_TOKEN; if (!token) { console.error('错误:未获取到TEAM_API_TOKEN环境变量'); process.exit(1); } // 改用for...of + await处理异步请求,避免脚本提前退出 for (const env of ['global', ...ENV_LIST]) { try { const res = await fetch( `[url to fetch]`, // 替换为实际的API地址 { headers: { Accept: 'application/json', Authorization: `Basic ${token}`, }, method: 'GET', }, ); const resText = await res.text(); const { content } = JSON.parse( JSON.parse(resText).results[0].body.atlas_doc_format.value, ); const filteredEnvList = content.filter(({ type }) => /heading|codeBlock/.test(type), ); const foundDevEnvIndex = filteredEnvList.findIndex( item => item.type === 'heading' && item.content[0].text.toLowerCase() === 'development', ); fs.writeFileSync( env === 'global' ? GLOBAL_ENV_DIR : getAppEnvDir(env), filteredEnvList[foundDevEnvIndex + 1].content[0].text + '\n', { encoding: 'utf8' }, ); console.log(`成功生成${env}的.env文件`); } catch (error) { console.error(`生成${env}的.env文件失败:`, error); process.exit(1); } }
2. 配置GitHub Secrets
在你的GitHub仓库中:
- 进入「Settings」→「Secrets and variables」→「Actions」
- 点击「New repository secret」
- 填写名称为
TEAM_API_TOKEN,值为你的团队API token,保存。
3. 编写GitHub Actions工作流文件
在仓库根目录创建.github/workflows/generate-env.yml文件,内容如下:
name: Generate .env Files on: # 可选:当推送到main分支时自动运行 push: branches: [ main ] # 可选:允许手动触发工作流 workflow_dispatch: jobs: generate-env: runs-on: ubuntu-latest steps: - name: 检出代码 uses: actions/checkout@v4 - name: 安装Node.js uses: actions/setup-node@v4 with: node-version: 20 # 选择兼容zx的Node.js版本 - name: 安装zx run: npm install -g zx - name: 运行生成.env脚本 env: # 将GitHub Secrets注入为环境变量 TEAM_API_TOKEN: ${{ secrets.TEAM_API_TOKEN }} run: zx path/to/your/script.mjs # 替换为脚本的实际路径 # 可选:如果需要将生成的.env文件提交到仓库,添加以下步骤 - name: 提交.env文件 run: | git config --global user.name "GitHub Actions" git config --global user.email "actions@github.com" git add .env apps/*/.env git commit -m "chore: update .env files via GitHub Actions" || echo "没有需要提交的变更" git push
关键注意事项
- 路径校验:确保脚本中
GLOBAL_ENV_DIR和getAppEnvDir的路径在GitHub Actions环境中正确(工作流默认工作目录是仓库根目录)。 - 异步处理:原脚本使用
forEach搭配异步fetch,会导致脚本在请求未完成时就退出,改用for...of+await可以保证所有请求完成后再结束脚本。 - 权限控制:如果需要提交.env文件到仓库,确保GitHub Actions有仓库的写入权限(默认的
GITHUB_TOKEN已经具备该权限)。
内容的提问来源于stack exchange,提问作者Chanwoo Park
相关产品推荐
相关产品推荐

