使用Terraform创建GitHub组织规则集时遇Workflows验证错误
解决Terraform创建GitHub组织规则集时的422 "Invalid rules: 'Workflows'"错误
问题场景
尝试通过Terraform为GitHub组织创建规则集,参考官方文档编写配置后,terraform plan输出无异常,但执行terraform apply时返回422验证失败错误:
│ Error: POST https://api.github.com/orgs/fancom-test-org/rulesets: 422 Validation Failed [{Resource: Field: Code: Message:Invalid rules: 'Workflows'}] │ │ with module.github_test_org.github_organization_ruleset.rules_semgrep[0], │ on ../org-settings/main.tf line 154, in resource "github_organization_ruleset" "rules_semgrep": │ 154: resource "github_organization_ruleset" "rules_semgrep" {
原配置代码片段:
# Fetch the repository ID using the repository name data "github_repository" "semgrep_repo" { full_name = "${var.org_name}/semgrep-caller-${var.org_name}" } resource "github_organization_ruleset" "rules_semgrep" { count = var.enable_semgrep ? 1 : 0 name = "semgrep_sca_iac" target = "branch" enforcement = "evaluate" conditions { ref_name { include = ["~DEFAULT_BRANCH"] exclude = [] } repository_name { include = ["~ALL"] exclude = [] } } bypass_actors { actor_id = 1 actor_type = "OrganizationAdmin" bypass_mode = "always" } rules { deletion = true required_workflows { required_workflow { repository_id = data.github_repository.semgrep_repo.repo_id path = "semgrep-caller-${var.org_name}/.github/workflows/semgrep_caller.yml" ref = "main" } } } }
解决方案
错误根源是required_workflow的path参数格式错误:不需要包含仓库名称前缀,只需填写工作流文件在目标仓库内的相对路径。
修改rules块中的path配置:
rules { deletion = true required_workflows { required_workflow { repository_id = data.github_repository.semgrep_repo.repo_id path = ".github/workflows/semgrep_caller.yml" # 移除仓库名称前缀 ref = "main" } } }
额外检查点
- 确认
data.github_repository.semgrep_repo获取的仓库ID正确,且目标工作流文件确实存在于该仓库的main分支下的对应路径 - 确保使用的GitHub Terraform Provider是最新版本,避免版本兼容性问题
内容的提问来源于stack exchange,提问作者Diego
相关产品推荐
相关产品推荐

