GitHub Actions运行CI拉取sidekiq-pro报401未授权错误咨询
问题根因
你遇到的401未授权错误是配置错误导致的,核心问题有3个:
- 认证变量作用域错误:你把
SIDEKIQ_PRO_USER、SIDEKIQ_PRO_PWD两个密钥变量只配置在了test任务下,lint任务无法读取到这两个值,拉取私有gem时自然没有认证信息。 - 认证配置时机错误:
ruby/setup-ruby开启bundler-cache: true参数时,会在当前步骤自动执行bundle install安装所有依赖。你把bundle私有源配置写在了后续的安全审计步骤中,执行到配置命令时gem已经下载失败了。 - 语法错误:
- 配置bundle源的命令前错误使用了管道符
|,实际是把bundler-audit的输出传给bundle config命令,根本不会执行认证配置 - 密钥插值语法写错,GitHub Actions的secrets读取格式为
${{ secrets.XXX }},你写的${secrets.XXX}是shell变量语法,无法读取到Actions中配置的密钥 - 附带问题:postgres服务配置缺少
POSTGRES_PASSWORD环境变量,启动时会直接报错,且test任务完全缺失steps定义,无法正常执行。
- 配置bundle源的命令前错误使用了管道符
修复后的完整配置参考
jobs: test: runs-on: ubuntu-latest services: postgres: image: postgres:13-alpine ports: - "5432:5432" options: >- --health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5 env: POSTGRES_DB: rails_test POSTGRES_PASSWORD: password env: RAILS_ENV: test DATABASE_URL: "postgres://rails:password@localhost:5432/rails_test" SIDEKIQ_PRO_USER: ${{ secrets.SIDEKIQ_PRO_USER }} SIDEKIQ_PRO_PWD: ${{ secrets.SIDEKIQ_PRO_PWD }} steps: - name: Checkout code uses: actions/checkout@v3 - name: Configure Sidekiq Pro gem source auth run: bundle config set gems.contribsys.com $SIDEKIQ_PRO_USER:$SIDEKIQ_PRO_PWD - name: Install Ruby and gems uses: ruby/setup-ruby@v1.92 with: bundler-cache: true # 后续自行添加测试执行步骤,比如bundle exec rspec lint: runs-on: ubuntu-latest env: SIDEKIQ_PRO_USER: ${{ secrets.SIDEKIQ_PRO_USER }} SIDEKIQ_PRO_PWD: ${{ secrets.SIDEKIQ_PRO_PWD }} steps: - name: Checkout code uses: actions/checkout@v3 - name: Configure Sidekiq Pro gem source auth run: bundle config set gems.contribsys.com $SIDEKIQ_PRO_USER:$SIDEKIQ_PRO_PWD - name: Install Ruby and gems uses: ruby/setup-ruby@v1.92 with: bundler-cache: true - name: Security audit dependencies run: bin/bundler-audit --update - name: Security audit application code run: bin/brakeman -q -w2 - name: Lint Ruby files run: bin/rubocop --parallel
验证Secrets是否正确注入的方法
注意:禁止直接打印密钥完整值,会造成敏感信息泄露,仅通过长度、前缀片段校验即可
在需要验证的任务steps中,添加如下调试步骤,放在变量配置完成后、依赖安装前即可:
- name: Debug credential injection run: | echo "SIDEKIQ_PRO_USER length: ${#SIDEKIQ_PRO_USER}" echo "SIDEKIQ_PRO_USER prefix: ${SIDEKIQ_PRO_USER:0:2}" echo "SIDEKIQ_PRO_PWD length: ${#SIDEKIQ_PRO_PWD}"
如果控制台打印的长度和你在仓库Secrets中配置的值长度一致,说明变量已经正确注入。
另外需要提前确认:密钥是配置在仓库Settings > Secrets and variables > Actions路径下的Repository secrets中,名称和配置中引用的完全一致,无多余空格、拼写错误。
内容的提问来源于stack exchange,提问作者HalleyRios
相关产品推荐
相关产品推荐

