iT邦幫忙

2026 iThome 鐵人賽

DAY 18
0
Build on Google AI

打造專屬 AI 參謀群:以 Gemini Spark、Workspace 與 ADK 構建自動化決策雷達系列 第 18 篇

Day 18:無人值守運作:配置 GitHub Actions 排程巡航與安全密鑰管理

  • 分享至 

  • xImage
  •  

在 Day 17 中,我們完成了本地端與 CI 護城河的防護。在真正踏入雲端自動化前,我們需要把本機累積的成果推向 GitHub,並串聯雲端排程。


一、程式碼推進與環境適配

1. 調整 SheetsAdapter 適應雙軌環境

在本地執行時,我們使用本地檔案;而在 GitHub Actions 的虛擬機中,憑證會由環境變數動態注入。我們更新 src/adapters/sheets_adapter.py 的初始化函式,使其無縫兼容本機與雲端環境:

# src/adapters/sheets_adapter.py
import os
import gspread
from google.oauth2.service_account import Credentials

class SheetsAdapter:
    SCOPES = [
        "https://www.googleapis.com/auth/spreadsheets",
        "https://www.googleapis.com/auth/drive",
    ]

    def __init__(
        self,
        credentials_path: str = "service_account.json",
        spreadsheet_name: str = "Intelligence_Radar_Hub",
        worksheet_name: str = "raw_feed",
    ):
        sa_path = os.getenv("GOOGLE_APPLICATION_CREDENTIALS", credentials_path)
        if not os.path.exists(sa_path):
            raise FileNotFoundError(f"找不到服務帳號金鑰檔案: {sa_path}")

        creds = Credentials.from_service_account_file(sa_path, scopes=self.SCOPES)
        self.client = gspread.authorize(creds)

        spreadsheet_id = os.getenv("SPREADSHEET_ID")
        self.sheet = self.client.open_by_key(spreadsheet_id) if spreadsheet_id else self.client.open(spreadsheet_name)
        self.worksheet = self.sheet.worksheet(worksheet_name)

2. 本地提交與初次推送

確保 .gitignore 已封鎖敏感檔案後,將架構代碼推上遠端:

git init
git add .
git commit -m "feat: complete agents pipeline and deploy actions workflow"
git branch -M main
git remote add origin https://github.com/<your-username>/intelligence-radar.git
git push -u origin main


二、建立排程巡航工作流(.github/workflows/patrol.yml)

當代碼推送後,我們在 .github/workflows/patrol.yml 定義巡航任務。此腳本結合了 先測後跑(Test-first)、Base64 金鑰動態解密 與 事後銷毀 機制:

# .github/workflows/patrol.yml
name: Intelligence Radar Scheduled Patrol

on:
  schedule:
    # 每天 UTC 01:00 / 09:00 / 17:00 執行 (台灣時間 09:00 / 17:00 / 01:00)
    - cron: '0 1,9,17 * * *'
  workflow_dispatch: # 支援手動即時觸發

jobs:
  patrol:
    name: Run Intelligence Pipeline
    runs-on: ubuntu-latest

    steps:
      - name: Checkout Code
        uses: actions/checkout@v4

      - name: Set up Python 3.11
        uses: actions/setup-python@v5
        with:
          python-version: "3.11"
          cache: "pip"

      - name: Install Dependencies
        run: |
          python -m pip install --upgrade pip
          pip install pytest ruff
          pip install -r requirements.txt

      - name: Pre-flight Verification (Lint & Tests)
        run: |
          ruff check .
          pytest tests/ -v

      - name: Decode Service Account Key
        env:
          GCP_SA_KEY_BASE64: ${{ secrets.GCP_SA_KEY_BASE64 }}
        run: |
          echo "$GCP_SA_KEY_BASE64" | base64 --decode > service_account.json
          chmod 600 service_account.json

      - name: Execute Intelligence Pipeline
        env:
          GEMINI_API_KEY: ${{ secrets.GEMINI_API_KEY }}
          SPREADSHEET_ID: ${{ secrets.SPREADSHEET_ID }}
          GOOGLE_APPLICATION_CREDENTIALS: service_account.json
        run: |
          python run_pipeline.py

      - name: Clean up Credentials
        if: always()
        run: |
          rm -f service_account.json


三、配置 GitHub Secrets 敏感憑證

進入儲存庫的 Settings ➔ 捲動左側選單至 Security 區塊 ➔ Secrets and variables ➔ Actions ➔ New repository secret,填入以下三組機密:

  1. GEMINI_API_KEY:Google AI Studio API Key(格式如 AQ.Ab8xxx...)。
  2. GCP_SA_KEY_BASE64:在本地終端機執行 base64 -i service_account.json | tr -d '\n' | pbcopy 後複製貼上的 Base64 字串。
  3. SPREADSHEET_ID:你的 Google Sheets 網址 /d/ 與 /edit 之間的那串字元 ID。

四、驗證全自動雲端巡航

設定完成後,切換回專案首頁頂部的 Actions 頁籤:

  1. 此時頁面已辨識出 Intelligence Radar Scheduled Patrol。
  2. 點選右側 Run workflow 觸發手動執行。
  3. 虛擬機會依序執行代碼檢查、解碼憑證、拉取 Google Sheets 上的 PENDING 條目,執行四階 Agent 分析並回填 PROCESSED,最終銷毀臨時憑證。

雷達系統至此已正式在雲端具備自主生命,達成無人值守巡航!


上一篇
Day 17:合約測試與 GitHub Actions CI 自動化守門:打造零 Token 成本的防護網
下一篇
Day 19:巡航哨兵監控:打造管線異常告警與 Webhook 即時推播
系列文
打造專屬 AI 參謀群:以 Gemini Spark、Workspace 與 ADK 構建自動化決策雷達 共 22 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言