Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Silent success when multiple auth methods are provided (zero review output, no error)

オープン
#519 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
55/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
静か
技術スタック
github-actions, google-cloud, typescript

調査の方向性

まず、run-gemini-cli@v0 の action の入力検証エントリーポイントを見つけ、競合する認証入力と、バックエンドを選択していない状態の WIF でワークフローを再現します。これらの警告が Actions ログにどのように出力されるかを確認します。完了の条件は、無効な設定がそれぞれ、競合する入力を明確に示すメッセージとともに 0 以外の終了コードで失敗し、検証出力が ACTIONS_STEP_DEBUG なしで表示されることです。

索引モデルが issue の本文から書いたものです。

説明

Summary

When a workflow passes multiple auth methods to run-gemini-cli@v0 simultaneously (e.g., both gcp_workload_identity_provider AND gemini_api_key and/or google_api_key), the action emits warnings but proceeds anyway. The job exits with conclusion: success, no error surface, but produces zero observable output — no review comments, no MCP tool calls visible in the log, no error message on the PR.

The same silent-success pattern occurs when WIF is configured but neither use_vertex_ai nor use_gemini_code_assist is set to true.

This is the worst possible failure mode for a CI tool: green check, no review, no clue why.

Why this is hard to diagnose

  • Job conclusion: success — no GitHub-level signal anything is wrong
  • The runner log shows env setup → context load → straight to "Post job cleanup" with nothing observable in between
  • No 4xx/5xx from Vertex AI or any other backend appears anywhere
  • No model output, no tool calls, no error trace
  • The action's validation warnings are only visible with ACTIONS_STEP_DEBUG=true as a repo secret

We spent several hours chasing quota limits, IAM roles, billing, and service-account permissions before enabling debug logging and finding the actual cause.

Reproduction

Workflow input that triggers silent failure:

uses: google-github-actions/run-gemini-cli@v0
with:
  gcp_workload_identity_provider: 'projects/.../providers/...'
  gcp_service_account: '[email protected]'
  gemini_api_key: '${{ secrets.GEMINI_API_KEY }}'    # competing
  google_api_key: '${{ secrets.GOOGLE_API_KEY }}'    # competing
  use_vertex_ai: 'true'

With this config:

  • All three auth methods are non-empty
  • The action emits warnings about ambiguity but does NOT fail
  • The job reports success with zero side effects

What the action actually emits (debug-only)

WARNING: Multiple authentication methods provided. Please use only one of
'gemini_api_key', 'google_api_key', or 'gcp_workload_identity_provider'.

WARNING: When using Workload Identity Federation, you must set exactly
one of 'use_vertex_ai' or 'use_gemini_code_assist' to 'true'.

Request

These warnings should be errors that fail the job, not warnings that proceed silently:

  1. If multiple non-empty auth methods are provided, exit non-zero with a clear message naming which inputs are conflicting.
  2. If WIF is used and neither use_vertex_ai nor use_gemini_code_assist is explicitly true, exit non-zero rather than running with no backend.
  3. Surface input-validation warnings to the standard log (not only the ##[debug] channel).

The current behavior makes the action effectively impossible to debug from a green-check status alone. Failing loudly on misconfig would turn "spent a day diagnosing a green-checkmark silent-no-op" into "30 seconds of reading the error".

Workaround

Configure exactly one auth method. We removed gemini_api_key and google_api_key from our workflows and rely on WIF + Vertex AI only — see our fix PR for the diff.

Action version

google-github-actions/run-gemini-cli@v0 (SHA f77273f4c914e4bf38440cf36a0369cb64a37489 at time of report)

主要言語
TypeScript
スター
2.1k
フォーク
287
PR マージ指標
30日以内にマージされた PR はありません

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

google-github-actions/run-gemini-cli のほかの issue

google-github-actions/run-gemini-cli の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。