GitLab CI/CD中Terraform AWS Provider依赖锁文件不一致问题求助
GitLab CI/CD Terraform Plan阶段锁文件缺失报错解决
问题场景
我在GitLab CI/CD上运行Terraform流水线,设置4个阶段:文件复制、Terraform Init、Terraform Plan、Terraform Apply。Init阶段执行成功,但Plan阶段报错提示依赖锁文件不一致,找不到AWS Provider的版本选择。
相关配置
Provider配置
terraform { required_providers { aws = { source = "hashicorp/aws" version = "~> 5.0" } } }
GitLab CI配置
copy-files: stage: copy-files script: - make copy-files terraform-init: stage: terraform-init script: - make terraform-init dependencies: - copy-files terraform-plan: stage: terraform-plan script: - make terraform-plan dependencies: - terraform-init
Makefile命令
# Copy Command copy-files: @echo "Copying file providers.tf and variables.tf to stack" @cp $(GENERIC_VARIABLES_DIR) $(TF_DIR) @cp $(GENERIC_PROVIDERS_DIR) $(TF_DIR) # Initialize Terraform terraform-init: @echo "Initializing environment..." terraform -chdir=$(TF_DIR) init -upgrade terraform validate # Plan command for the environment terraform-plan: @echo "Running terraform plan for environment..." terraform -chdir=$(TF_DIR) plan -var-file="variables.tfvars" # Apply command for the environment terraform-apply: @echo "Running terraform apply..." terraform -chdir=$(TF_DIR) apply -auto-approve -var-file="variables.tfvars"
报错信息
The following dependency selections recorded in the lock file are
inconsistent with the current configuration:
- provider registry.terraform.io/hashicorp/aws: required by this configuration but no version is selected
To make the initial dependency selections that will initialize the
dependency lock file, run: terraform init
问题根源是GitLab CI每个阶段独立克隆仓库,Init阶段生成的.terraform.lock.hcl没有传递到Plan阶段。
解决方法
方案1:用GitLab CI缓存保留锁文件
在CI配置中添加缓存规则,保留Terraform初始化后的锁文件和依赖目录,让后续阶段复用:
cache: paths: - ${TF_DIR}/.terraform.lock.hcl - ${TF_DIR}/.terraform/ copy-files: stage: copy-files script: - make copy-files terraform-init: stage: terraform-init script: - make terraform-init dependencies: - copy-files terraform-plan: stage: terraform-plan script: - make terraform-plan dependencies: - terraform-init
方案2:将锁文件作为制品传递
在Init阶段把.terraform.lock.hcl定义为制品,让Plan阶段依赖获取:
terraform-init: stage: terraform-init script: - make terraform-init dependencies: - copy-files artifacts: paths: - ${TF_DIR}/.terraform.lock.hcl expire_in: 1 hour # 按需设置过期时间 terraform-plan: stage: terraform-plan script: - make terraform-plan dependencies: - terraform-init
方案3:Plan阶段重新执行Init(应急用)
如果暂时无法配置缓存/制品,可修改Makefile的Plan目标,先执行Init再Plan(会增加流水线耗时):
terraform-plan: @echo "Running terraform plan for environment..." terraform -chdir=$(TF_DIR) init -upgrade -reconfigure terraform -chdir=$(TF_DIR) plan -var-file="variables.tfvars"
补充建议
- 确保
TF_DIR变量在所有CI阶段中一致,避免路径错误导致锁文件无法读取 - 优先选择缓存方案,能复用已下载的Provider,减少流水线执行时间
内容的提问来源于stack exchange,提问作者thom4s94
相关产品推荐
相关产品推荐

