导入本地状态至Terraform Cloud后Pubsub Schema认证失败求助
我配置了结合Terraform Cloud的GitHub Action来执行terraform plan,空状态下流程可正常运行,但导入本地状态后执行plan开始失败。本地环境按照HashiCorp官方文档导入状态:执行terraform login登录,在main.tf中添加Terraform Cloud配置块,执行terraform init后运行导入脚本,Terraform Cloud UI中已能看到状态内容。但执行plan时,所有pubsub schema资源均出现如下认证错误:
Error: Error when reading or editing PubsubSchema "projects/xxxx-dev/schemas/user_email_schema": Get "https://pubsub.googleapis.com/v1/projects/xxxxx-dev/schemas/user_email_schema?alt=json": private key should be a PEM or plain PKCS1 or PKCS8; parse error: asn1: structure error: tags don't match (16 vs {class:0 tag:13 length:45 isCompound:true}) {optional:false explicit:false application:false private:false defaultValue: tag: stringType:0 timeType:0 set:false omitEmpty:false} pkcs1PrivateKey @2
其他类型资源可正常执行plan。
资源定义
resource "google_pubsub_schema" "match_schema" { name = "match_schema" type = "AVRO" definition = file("${path.module}/schemas/match_schema.avsc") }
目录结构
project-root/ │ ├── infra/ │ └── schemas.tf │ └── schemas/ └── match_schema.avsc
Terraform Cloud状态信息
Terraform Cloud UI中match_schema的definition字段与本地文件内容一致,且所有资源的private键值相同。
内容的提问来源于stack exchange,提问作者Sarah

