Azure DevOps Terraform Pipeline中terraform show报错及成本估算故障排查
问题描述
在Azure DevOps CI/CD Pipeline中部署Azure存储账户或虚拟机时,引入Infracost插件做成本预估算。terraform plan执行成功并生成了tfplan文件,但执行terraform show命令时出现以下错误:
│ Error: Failed to load plugin schemas │ Error while loading schemas for plugin components: Failed to obtain │ provider schema: Could not load the schema for provider │ registry.terraform.io/hashicorp/azurerm: failed to instantiate provider │ "registry.terraform.io/hashicorp/azurerm": unavailable │ provider "registry.terraform.io/hashicorp/azurerm".
本地测试正常,但Pipeline中无法完成terraform show及成本估算,需要排查解决。
相关配置代码
Azure DevOps Pipeline配置
trigger: none pool: vmImage: 'ubuntu-latest' variables: - group: GenAISecrets parameters: - name: OrderID displayName: Please Provide the id:- type: object stages: - stage: InitializeAndValidate displayName: "Terraform Validate and Plan" jobs: - job: terraform_plan displayName: "Terraform Validate and Plan Job" steps: # Step 1: Install Terraform - task: TerraformInstaller@0 inputs: terraformVersion: 'latest' # Step 2: Initialize Terraform with Backend Configuration - task: TerraformTaskV3@3 displayName: "Terraform Init" inputs: provider: 'azurerm' command: 'init' workingDirectory: 'terraform' backendServiceArm: 'TEST' backendAzureRmResourceGroupName: $(ResourceGroup) backendAzureRmStorageAccountName: $(StorageAccount) backendAzureRmContainerName: $(Container) backendAzureRmKey: '${{ parameters.OrderID }}.tfstate' # Step 3: Terraform Validate to Check Configuration Files - task: TerraformTaskV3@3 displayName: "Terraform Validate" inputs: provider: 'azurerm' command: 'validate' - task: TerraformTaskV3@3 displayName: "Terraform Plan" inputs: provider: 'azurerm' command: 'plan' workingDirectory: 'terraform' environmentServiceNameAzureRM: 'TEST' commandOptions: '-var-file=terraform.tfvars -out=$(System.DefaultWorkingDirectory)/tfplan' - script: | terraform show -json $(System.DefaultWorkingDirectory)/tfplan > planned_resources.json ##facing error here displayName: "Export Planned Resources to JSON" # Step 4: Infracost Cost Estimation - task: InfracostSetup@2 displayName: "Estimate Costs with Infracost" inputs: planPath: "$(System.DefaultWorkingDirectory)/tfplan" # Path to the Terraform plan usageFile: "infracost-usage.yml" apiKey: $(infracostApiKey) # API Key from Azure DevOps secrets outputFormat: "json" # Output format (e.g., json, table, etc.) outputPath: "$(System.DefaultWorkingDirectory)/infracost.json" - script: | echo "Files after terraform plan:" ls -al displayName: "List Files After Plan" # Step 6: Publish Cost Estimation Artifact - task: PublishPipelineArtifact@1 inputs: targetPath: "$(System.DefaultWorkingDirectory)/infracost.json" artifactName: "CostEstimation" publishLocation: "pipeline" displayName: "Publish Cost Estimation"
main.tf
# main.tf resource "azurerm_resource_group" "storage_rg" { name = var.resource_group_name location = var.region } resource "azurerm_storage_account" "storage_account" { name = var.storage_account_name resource_group_name = azurerm_resource_group.storage_rg.name location = azurerm_resource_group.storage_rg.location account_tier = "Standard" account_replication_type = "LRS" }
provider.tf
# provider.tf terraform { required_providers { azurerm = { source = "hashicorp/azurerm" version = ">=4.6.0" } } backend "azurerm" {} } provider "azurerm" { use_oidc = true features {} }
variable.tf
# variable.tf variable "region" { description = "The Azure region to deploy resources." type = string } variable "resource_group_name" { description = "The name of the resource group." type = string } variable "storage_account_name" { description = "The name of the storage account." type = string validation { condition = length(var.storage_account_name) >= 3 && length(var.storage_account_name) <= 24 error_message = "Storage account name must be between 3 and 24 characters long and contain only lowercase letters and numbers." } }
解决方案
问题核心是Pipeline执行terraform show和Infracost任务时,无法找到Terraform初始化阶段下载的azurerm插件,原因有两点:
terraform show在根目录执行,而插件存放在terraform子目录的.terraform文件夹中- 直接调用系统terraform命令,未继承TerraformTaskV3任务的环境配置
修复步骤1:切换工作目录执行terraform show
修改Export Planned Resources to JSON步骤,先切换到terraform目录再执行命令:
- script: | cd terraform terraform show -json $(System.DefaultWorkingDirectory)/tfplan > $(System.DefaultWorkingDirectory)/planned_resources.json displayName: "Export Planned Resources to JSON"
修复步骤2:指定Infracost工作目录
Infracost需要访问Terraform插件解析tfplan,添加workingDirectory参数指向terraform目录:
- task: InfracostSetup@2 displayName: "Estimate Costs with Infracost" inputs: workingDirectory: 'terraform' planPath: "$(System.DefaultWorkingDirectory)/tfplan" usageFile: "infracost-usage.yml" apiKey: $(infracostApiKey) outputFormat: "json" outputPath: "$(System.DefaultWorkingDirectory)/infracost.json"
额外优化:统一Terraform版本
避免使用latest版本,指定与本地一致的具体版本(如1.5.7),减少兼容性问题:
- task: TerraformInstaller@0 inputs: terraformVersion: '1.5.7' # 替换为你本地使用的版本
修改后重新运行Pipeline,terraform show和Infracost任务即可正常执行,成功生成目标文件。
内容的提问来源于stack exchange,提问作者User
相关产品推荐
相关产品推荐

