CloudBuild无法拉取公开GitHub Terraform模块部署GKE的问题求助
我们尝试使用Google公开Terraform模块,在客户环境的GitHub托管Terraform代码中部署GKE集群,但CloudBuild触发器运行构建时持续失败。
相关代码
cluster.tf 初始配置
module "gke_cluster" { source = "terraform-google-modules/kubernetes-engine/google//modules/beta-autopilot-public-cluster" version = "~> 30.0" # 其他配置省略 }
cloudbuild.yaml 配置
steps: - name: "hashicorp/terraform" entrypoint: sh args: - '-c' - | terraform init && terraform plan options: logging: CLOUD_LOGGING_ONLY
报错信息
初始配置运行时的报错:
failed to download module..
could not download module from https://github.com/terraform-google-modules/kubernetes-engine/google//modules/beta-autopilot-public-cluster
/usr/bin/git exited with 1: git: 'credential-gcloud.sh' is not a git
Could not read username for https://github.com. No such device or address..
将模块源改为SSH地址后的报错:
Host key verification failed, could not read from remote repository,
make sure you've the correct access rights and the repository exists.
注:CloudBuild触发器关联的服务账号拥有Owner权限,区域为us-central1。
1. 重置Git凭证配置,避免无效认证尝试
CloudBuild使用的hashicorp/terraform容器中,Git默认配置了错误的凭证助手credential-gcloud.sh,导致拉取公开GitHub仓库时触发不必要的认证流程。修改cloudbuild.yaml,在terraform init前重置Git凭证配置:
steps: - name: "hashicorp/terraform" entrypoint: sh args: - '-c' - | git config --global credential.helper "" terraform init && terraform plan options: logging: CLOUD_LOGGING_ONLY
2. 使用Terraform Registry官方源而非直接Git链接
保持cluster.tf中的模块源为Terraform Registry格式,这是官方推荐的拉取方式,无需手动处理Git克隆逻辑:
module "gke_cluster" { source = "terraform-google-modules/kubernetes-engine/google//modules/beta-autopilot-public-cluster" version = "~> 30.0" # 其他配置... }
3. 避免使用SSH方式拉取公开模块
公开仓库无需SSH认证,且CloudBuild容器默认没有配置GitHub的SSH密钥和Host Key,因此不要使用git@github.com:开头的SSH源地址,优先使用HTTPS或Registry格式的源。
4. 确认CloudBuild网络访问权限
确保CloudBuild触发器使用的是默认网络配置(允许访问公网),如果使用私有VPC,需配置VPC连接器并确保出站规则允许访问GitHub和Terraform Registry。
内容的提问来源于stack exchange,提问作者shagsb

