GitLab用户Runner模块创建与多Runner场景下token在Lambda的使用咨询
1. 创建gitlab_user_runner模块并使用根级Runner的token
模块搭建步骤
1.1 构建模块目录结构
在Terraform项目中创建如下目录结构:
modules/ └── gitlab_user_runner/ ├── main.tf ├── variables.tf └── outputs.tf
1.2 定义模块变量(variables.tf)
声明可配置参数,包含GitLab连接信息和Runner属性:
variable "gitlab_token" { type = string description = "GitLab管理员令牌,用于创建实例级(根级)Runner" sensitive = true } variable "gitlab_url" { type = string description = "GitLab实例URL,默认使用官方地址" default = "https://gitlab.com/" } variable "runner_description" { type = string description = "Runner的描述信息" } variable "runner_tags" { type = list(string) description = "Runner的标签列表" default = [] }
1.3 编写核心逻辑(main.tf)
使用gitlab_runner资源创建根级Runner,通过instance_level = true标记为实例级(根级):
provider "gitlab" { token = var.gitlab_token base_url = var.gitlab_url } resource "gitlab_runner" "instance_runner" { instance_level = true description = var.runner_description tags = var.runner_tags locked = false paused = false }
1.4 定义模块输出(outputs.tf)
输出Runner的token和配置文件内容,供父模块调用:
output "runner_token" { type = string description = "根级Runner的注册令牌" sensitive = true value = gitlab_runner.instance_runner.token } output "config_toml" { type = string description = "Runner的配置文件内容" value = gitlab_runner.instance_runner.config_toml }
1.5 调用模块并使用token
在项目根目录的main.tf中,每次新增模块实例即可创建新的根级Runner,并获取对应token:
module "root_runner_1" { source = "./modules/gitlab_user_runner" gitlab_token = var.gitlab_admin_token runner_description = "Root Runner 1" runner_tags = ["root", "general"] } module "root_runner_2" { source = "./modules/gitlab_user_runner" gitlab_token = var.gitlab_admin_token runner_description = "Root Runner 2" runner_tags = ["root", "build"] } # 示例:将多个根级Runner的token传入Lambda resource "aws_lambda_function" "example" { # 其他Lambda配置 environment { variables = { RUNNER_TOKEN_1 = module.root_runner_1.runner_token RUNNER_TOKEN_2 = module.root_runner_2.runner_token } } }
2. 多Runner实例的token输出与Lambda环境变量配置
核心结论
你当前的代码仅调用了一次project_runner模块,因此module.project_runner.runner_token只会输出这单个Runner的token,不存在"每次创建输出对应token"的情况——因为只创建了一个Runner实例。
实现多Runner并传递token的方案
方案1:多Runner实例对应多Lambda
每个Runner实例对应一个Lambda,各自使用专属token:
# 创建2个Runner实例 module "project_runner_1" { source = "./modules/gitlab_user_runner" runner_type = "project_type" runner_description = "Project Runner 1" } module "project_runner_2" { source = "./modules/gitlab_user_runner" runner_type = "project_type" runner_description = "Project Runner 2" } # 对应创建2个Lambda module "test-lambda-1" { function_name = "test-lambda-1" environment_variables = { GITLAB_TOKEN = module.project_runner_1.runner_token CONFIG_TOML = module.project_runner_1.config_toml } } module "test-lambda-2" { function_name = "test-lambda-2" environment_variables = { GITLAB_TOKEN = module.project_runner_2.runner_token CONFIG_TOML = module.project_runner_2.config_toml } }
方案2:批量创建Runner并将所有token传入单个Lambda
使用for_each批量生成Runner,将所有token整合后传入Lambda:
# 定义Runner配置列表 locals { runners = { runner_1 = { description = "Project Runner 1", tags = ["project", "test"] } runner_2 = { description = "Project Runner 2", tags = ["project", "build"] } } } # 批量创建Runner模块 module "project_runners" { source = "./modules/gitlab_user_runner" for_each = local.runners runner_type = "project_type" runner_description = each.value.description runner_tags = each.value.tags } # 将所有Runner的token拼接后传入Lambda module "test-lambda" { function_name = "test-lambda" environment_variables = { GITLAB_TOKENS = join(",", values(module.project_runners)[*].runner_token) CONFIG_TOMLS = join("\n---\n", values(module.project_runners)[*].config_toml) } }
内容的提问来源于stack exchange,提问作者2024KD
相关产品推荐
相关产品推荐

