You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps Terraform YAML配置:实现apply命令手动审批

解决Azure DevOps Pipeline中Terraform Apply自动执行的问题

针对你担心Terraform Apply自动执行可能引发资源销毁的问题,有两种常用的配置方式实现手动确认/审批后再执行:

方法1:利用Azure DevOps环境审批控制Deploy作业

在Azure DevOps中创建带审批机制的环境,让Deploy作业必须经过审批才能启动:

  1. 登录Azure DevOps,进入你的项目 → 管道 → 环境,新建一个环境(比如命名为Production),在环境设置中添加审批人。
  2. 修改Pipeline YAML,在Deploy作业中引用该环境:
trigger:
- main

pool:
  vmImage: ubuntu-latest

jobs:
- job: Validate
  displayName: Terraform Validate
  pool:
    vmImage: ubuntu-latest
  steps:
  - checkout: self
  - task: TerraformInstaller@0
    displayName: Install Terraform latest
  - task: TerraformTaskV2@2
    displayName: 'Terraform : Init'
    inputs:
      backendServiceArm: 'serviceaccount-test'
      backendAzureRmResourceGroupName: dowd-resourcegroup-test
      backendAzureRmStorageAccountName: dowdtftestest
      backendAzureRmContainerName: tfstatedowd
      backendAzureRmKey: terraform.tfstate
  - task: TerraformTaskV2@2
    displayName: 'Terraform : Validate'
    inputs:
      command: validate
- job: Deploy
  displayName: Terraform Deploy
  pool:
    vmImage: ubuntu-latest
  environment: 'Production' # 引用带审批的环境
  steps:
  - checkout: self
  - task: TerraformInstaller@0
    displayName: Install Terraform latest
  - task: TerraformTaskV2@2
    displayName: 'Terraform : Init'
    inputs:
      backendServiceArm: 'serviceaccount-test'
      backendAzureRmResourceGroupName: dowd-resourcegroup-test
      backendAzureRmStorageAccountName: dowdtftestest
      backendAzureRmContainerName: tfstatedowd
      backendAzureRmKey: terraform.tfstate
  - task: TerraformTaskV2@2
    displayName: 'Terraform : Plan'
    inputs:
      command: plan
      environmentServiceNameAzureRM: 'serviceaccount-test'
      publishPlanResults: 'TF_Plan_Result' # 发布Plan结果到Pipeline,方便审批人查看
  - task: TerraformTaskV2@2
    displayName: 'Terraform : Validate and Apply'
    inputs:
      command: apply
      environmentServiceNameAzureRM: 'serviceaccount-test'

配置后,每次触发Pipeline时,Validate作业会自动执行,而Deploy作业需要等待审批人确认后才会启动,审批人可以在Pipeline页面查看Terraform Plan的变更详情。

方法2:在Pipeline中插入手动验证步骤

如果不想创建环境,可以直接在Plan和Apply之间添加ManualValidation任务,强制要求手动确认后再执行Apply:

trigger:
- main

pool:
  vmImage: ubuntu-latest

jobs:
- job: Validate
  displayName: Terraform Validate
  pool:
    vmImage: ubuntu-latest
  steps:
  - checkout: self
  - task: TerraformInstaller@0
    displayName: Install Terraform latest
  - task: TerraformTaskV2@2
    displayName: 'Terraform : Init'
    inputs:
      backendServiceArm: 'serviceaccount-test'
      backendAzureRmResourceGroupName: dowd-resourcegroup-test
      backendAzureRmStorageAccountName: dowdtftestest
      backendAzureRmContainerName: tfstatedowd
      backendAzureRmKey: terraform.tfstate
  - task: TerraformTaskV2@2
    displayName: 'Terraform : Validate'
    inputs:
      command: validate
- job: Deploy
  displayName: Terraform Deploy
  pool:
    vmImage: ubuntu-latest
  steps:
  - checkout: self
  - task: TerraformInstaller@0
    displayName: Install Terraform latest
  - task: TerraformTaskV2@2
    displayName: 'Terraform : Init'
    inputs:
      backendServiceArm: 'serviceaccount-test'
      backendAzureRmResourceGroupName: dowd-resourcegroup-test
      backendAzureRmStorageAccountName: dowdtftestest
      backendAzureRmContainerName: tfstatedowd
      backendAzureRmKey: terraform.tfstate
  - task: TerraformTaskV2@2
    displayName: 'Terraform : Plan'
    inputs:
      command: plan
      environmentServiceNameAzureRM: 'serviceaccount-test'
      publishPlanResults: 'TF_Plan_Result' # 发布Plan结果
  # 插入手动验证步骤
  - task: ManualValidation@0
    displayName: '确认Terraform Plan变更'
    inputs:
      notifyUsers: '审批人的邮箱或Azure DevOps用户名'
      instructions: '请查看Terraform Plan的变更内容,确认无误后点击批准继续执行Apply'
      onTimeout: 'reject' # 超时自动拒绝
  - task: TerraformTaskV2@2
    displayName: 'Terraform : Validate and Apply'
    inputs:
      command: apply
      environmentServiceNameAzureRM: 'serviceaccount-test'

这个配置下,Pipeline执行到ManualValidation步骤会暂停,需要指定的审批人登录Azure DevOps查看Plan详情,手动点击批准后,才会继续执行Terraform Apply。

额外建议

  • 开启publishPlanResults参数后,Plan的变更详情会直接显示在Pipeline页面,方便审批人快速核对变更内容,避免误操作。
  • 可以配合Terraform Plan的输出文件,用PublishBuildArtifacts任务将Plan文件上传为构建产物,方便后续追溯。

内容的提问来源于stack exchange,提问作者balaganesh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 04:52:50