如何在github工作流中设置秘密,该秘密被注入不在WorkFlow文件夹中的属性文件中
我有一个.github/WorkFlow .yml文件,该文件用作GitHub Action Workflow。
请忍受我,我是Github的新手。
每当更改项目中的文件时,我正在研究一个项目,以触发GitHub的构建。我有那一部分工作。但是,有人告诉我,我们不应该有任何包含用户名/密码的文件,并且我们应该用github秘密替换它们。我在某个地方阅读了GitHub秘密仅在.github/WorkFlow目录中的文件上工作的地方。不幸的是,我知道的用户名/密码在.properties文件中,与.github/workflow不同。有没有办法将GitHub秘密注入.github/Workflow中未找到的文件?
一些可能的方法:
在build.yml文件中,我可以设置一个与github秘密相等的全局环境变量,然后在.properties文件中使用环境变量(例如:$ {$ {env.mypassword}})。那对我不起作用。
我可以在build.yml文件中调用bash脚本以将其作为输入秘密,然后bash脚本可以继续使用输入附加.properties文件。该秘密将可用于bash脚本,因为它在build.yml文件中,在.github/workflow文件中,在同一外壳中。我还没有尝试过。
I have a .github/workflow .yml file that I am using as a GitHub Action workflow.
Please bear with me I am new to GitHub.
I am working on a project to trigger a build in GitHub whenever a file in the project is changed. I have that part working. However, I was told that we shouldn't have any files that contain username/passwords, and that we should replace them with GitHub secrets. I read somewhere that GitHub secrets only work on files in .github/workflow directory. Unfortunately, the username/passwords I know about are in .properties files, in a different directory than .github/workflow. Is there a way to inject GitHub secrets into a file not found in .github/workflow?
Some possible approaches:
In the build.yml file, I can set a global environment variable equal to the GitHub secret, then use the environment variable in the .properties file (eg: ${{env.mypassword}}). That hasn't worked for me.
I could call a bash script in the build.yml file to take as input the secret, and then the bash script could proceed to append the .properties file with the input. The secret would be available to the bash script since its called within the build.yml file, in the .github/workflow file, in the same shell. I haven't tried this yet.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
也许您可以向Env注入,然后如您所说的那样发送到您的bash脚本。
另外,创建github操作位于位置:
repo->设置/秘密/操作
maybe you can inject with env and then send to your bash script as you said.
also, create github actions is on the location:
repo -> settings/secrets/actions