使用Terragrunt集成Atlantis时出现配置报错求助
问题排查:Atlantis 解析 atlantis.yaml 报错
背景信息
我正基于Terraform、Terragrunt和Atlantis搭建GitOps环境,已手动在服务器部署Atlantis。仓库内包含以下配置文件:
- 仓库根目录的
atlantis.yaml(项目配置) - 启动Atlantis时指定的服务器端
atlantis.yaml(工作流配置)
仓库端 atlantis.yaml 配置
version: 3 automerge: true projects: - name: meetup--us-east-1--eks dir: meetup/us-east-1/eks workflow: terragrunt terraform_version: v1.3.6 autoplan: when_modified: - '**/**' - name: meetup--us-east-1--vpc dir: meetup/us-east-1/vpc workflow: terragrunt terraform_version: v1.3.6 autoplan: when_modified: - '**/**'
服务器端 atlantis.yaml 配置
repos: - id: github.com/samrepos/* workflow: terragrunt allowed_overrides: [workflow] allowed_workflows: [terragrunt] allow_custom_workflows: false workflows: terragrunt: plan: steps: - run: TERRAGRUNT_TFPATH=terraform$ATLANTIS_TERRAFORM_VERSION terragrunt plan -no-color -out $PLANFILE apply: steps: - run: TERRAGRUNT_TFPATH=terraform$ATLANTIS_TERRAFORM_VERSION terragrunt apply -no-color $PLANFILE
启动Atlantis的命令
atlantis server --atlantis-url="http://10.0.0.17" --gh-user="samrepos" --gh-token="123" --gh-webhook-secret="123" --repo-allowlist="github.com/samrepos/terragrunt" --config=atlantis.yaml
报错信息
{"level":"error","ts":"2023-11-14T20:37:32.385Z","caller":"events/pull_updater.go:17","msg":"parsing atlantis.yaml: repo config not allowed to set 'workflow' key: server-side config needs 'allowed_overrides: [workflow]'","json":{"repo":"samrepos/terragrunt","pull":"12"},"stacktrace":"github.com/runatlantis/atlantis/server/events.(*PullUpdater).updatePull\n\t/home/runner/work/atlantis/atlantis/server/events/pull_updater.go:17\ngithub.com/runatlantis/atlantis/server/events.(*PlanCommandRunner).run\n\t/home/runner/work/atlantis/atlantis/server/events/plan_command_runner.go:199\ngithub.com/runatlantis/atlantis/server/events.(*PlanCommandRunner).Run\n\t/home/runner/work/atlantis/atlantis/server/events/plan_command_runner.go:292\ngithub.com/runatlantis/atlantis/server/events.(*DefaultCommandRunner).RunCommentCommand\n\t/home/runner/work/atlantis/atlantis/server/events/command_runner.go:328"}
问题分析
报错核心原因:仓库端的atlantis.yaml在项目层级指定了workflow字段,但服务器端配置的权限逻辑未允许该操作。虽然服务器端配置中写了allowed_overrides: [workflow],但当前场景下存在冗余配置:服务器端已经为github.com/samrepos/*仓库设置了默认工作流terragrunt,仓库端的项目配置无需重复指定该字段。
解决步骤
方案1:移除仓库端atlantis.yaml中的workflow字段
由于服务器端已经为整个仓库指定了默认工作流,项目层级无需重复配置。修改后的仓库端atlantis.yaml如下:
version: 3 automerge: true projects: - name: meetup--us-east-1--eks dir: meetup/us-east-1/eks terraform_version: v1.3.6 autoplan: when_modified: - '**/**' - name: meetup--us-east-1--vpc dir: meetup/us-east-1/vpc terraform_version: v1.3.6 autoplan: when_modified: - '**/**'
额外清理
仓库内的repo.yaml文件属于冗余配置,因为启动Atlantis时已经指定了服务器端的atlantis.yaml,可以直接删除该文件避免混淆。
内容的提问来源于stack exchange,提问作者Eva
相关产品推荐
相关产品推荐

