You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否用Terraform+Azure DevOps Pipelines部署至本地虚拟机内的非云K8s集群?

可行,该方案已被大量开发者实践落地

核心实现思路

Azure DevOps的Kubernetes服务连接/环境会自动在流水线中注入集群访问凭证,你可以通过两种方式获取kubeconfig来配置Terraform的Kubernetes Provider:

方式1:直接复用Azure DevOps自动注入的环境变量

当你的deployment任务关联了Kubernetes类型的environment时,Azure DevOps会自动设置KUBECONFIG环境变量,指向临时生成的kubeconfig文件路径。

在Terraform的Kubernetes Provider配置中,无需额外指定路径,Provider会自动读取该环境变量:

provider "kubernetes" {
  # 自动读取KUBECONFIG环境变量指向的配置文件
}

方式2:手动导出kubeconfig到指定路径(更灵活)

如果需要自定义kubeconfig的存储位置,可通过Kubectl任务导出:

- task: Kubectl@0
  displayName: Export kubeconfig
  inputs:
    command: 'config'
    arguments: 'view --raw > $(Agent.TempDirectory)/custom-kubeconfig'

然后在Terraform Provider中指定该路径:

provider "kubernetes" {
  config_path = "$(Agent.TempDirectory)/custom-kubeconfig"
}

修改后的流水线示例(替换Helm为Terraflow)

基于你提供的原有流水线,调整为Terraform部署的版本:

stages:
  - stage: DEV
    condition: eq(variables.environment, 'DEV')
    jobs:
      - deployment:
        displayName: "Deploy ${{parameters.environment}} infrastructure with Terraform"
        environment:
          name: 01-DEV
          resourceType: Kubernetes
        variables:
          - group: "dev"
        workspace:
          clean: all
        strategy:
          runOnce:
            deploy:
              steps:
                - checkout: self

                - task: gitversion/setup@0
                  displayName: Setup GitVersion
                  inputs:
                    versionSpec: '5.x'

                - task: gitversion/execute@0
                  displayName: Execute GitVersion
                  inputs:
                    useConfigFile: true
                    configFilePath: $(gitVersionFile)

                # 安装指定版本的Terraform
                - task: TerraformInstaller@0
                  displayName: Install Terraform
                  inputs:
                    terraformVersion: '1.5.x' # 按需调整版本

                # Terraform初始化(如果使用远程后端需配置对应参数)
                - task: TerraformTaskV4@4
                  displayName: Terraform Init
                  inputs:
                    provider: 'azurerm' # 若无需Azure资源可忽略或调整
                    command: 'init'
                    workingDirectory: '$(Build.SourcesDirectory)/terraform' # 你的Terraform代码根目录
                    backendServiceArm: '你的Azure服务连接名称'
                    backendAzureRmResourceGroupName: '你的状态存储资源组'
                    backendAzureRmStorageAccountName: '你的状态存储账户'
                    backendAzureRmContainerName: 'tfstate-container'
                    backendAzureRmKey: 'dev.tfstate'

                # 生成部署规划
                - task: TerraformTaskV4@4
                  displayName: Terraform Plan
                  inputs:
                    provider: 'azurerm'
                    command: 'plan'
                    workingDirectory: '$(Build.SourcesDirectory)/terraform'
                    commandOptions: '-out=tfplan -var "environment=$(environment)" -var "build_number=$(Build.BuildNumber)"'

                # 执行部署
                - task: TerraformTaskV4@4
                  displayName: Terraform Apply
                  inputs:
                    provider: 'azurerm'
                    command: 'apply'
                    workingDirectory: '$(Build.SourcesDirectory)/terraform'
                    commandOptions: 'tfplan'

关键注意事项

  • 因为你之前的Helm部署能正常运行,说明Azure DevOps的服务连接已具备集群访问权限,Terraform复用该连接即可正常工作
  • 若Terraform同时管理Azure云资源和K8s资源,需确保Azure服务连接和Kubernetes服务连接的权限配置正确
  • 可保留原有environment关联逻辑,Azure DevOps会自动处理集群访问的权限验证,无需手动维护kubeconfig凭证

内容的提问来源于stack exchange,提问作者Jase

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 20:03:20