GitHub Action中Terraform -detailed-exitcode参数无法正常生效
Terraform Plan -detailed-exitcode在GitHub Actions中返回码异常问题
Terraform的terraform plan -detailed-exitcode参数,在命令执行成功且存在资源差异时应返回退出码2。但在GitHub工作流中使用hashicorp/setup-terraform action执行该命令时,即便存在资源变更(如示例中的新建告警策略),退出码仍为0;本地手动执行则正常返回退出码2。尝试过Bash和PowerShell两种脚本写法,问题依旧。
GitHub工作流配置
name: 'Terraform: Main' on: workflow_call: inputs: environment: required: true type: string permissions: contents: read id-token: write pull-requests: write env: working_directory: ./terraform jobs: terraform_check_changes: runs-on: ubuntu-latest environment: ${{ inputs.environment }} steps: - name: Checkout Repository uses: actions/checkout@v3 - name: "Terraform: Setup" uses: hashicorp/setup-terraform@v2 with: terraform_version: 1.6.0 - name: "Terraform: Init" id: init run: terraform init -backend-config use_azuread_auth=false -backend-config use_oidc=true shell: bash working-directory: ${{ env.working_directory }} env: ARM_CLIENT_ID: ${{ vars.AZURE_CLIENT_ID }} - name: "Terraform: Plan" id: plan run: | set +e terraform plan -var "new_relic_api_key=${{ secrets.NEW_RELIC_API_KEY }}" -var-file environments/${{ inputs.environment}}.tfvars -no-color -detailed-exitcode exitcode=$? echo "Terraform exited with $exitcode" if [[ $exitcode -eq 2 ]]; then echo "planHasChanges=true" >> "$GITHUB_OUTPUT" exit 0 else exit $exitcode fi shell: bash working-directory: ${{ env.working_directory }} env: ARM_CLIENT_ID: ${{ vars.AZURE_CLIENT_ID }}
Plan步骤执行输出
/home/runner/work/_temp/9efc414b-0934-467d-902b-9926937a2e8f/terraform-bin plan -var new_relic_api_key=*** -var-file environments/dev.tfvars -no-color -detailed-exitcode Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols: + create Terraform will perform the following actions: # newrelic_alert_policy.kamil_test_policy will be created + resource "newrelic_alert_policy" "kamil_test_policy" { + account_id = (known after apply) + id = (known after apply) + incident_preference = "PER_POLICY" + name = "Kamil's Terraform test" } Plan: 1 to add, 0 to change, 0 to destroy. ───────────────────────────────────────────────────────────────────────────── Note: You didn't use the -out option to save this plan, so Terraform can't guarantee to take exactly these actions if you run "terraform apply" now. Terraform exited with 0
尝试的PowerShell脚本
- name: "Terraform: Plan" id: plan run: | terraform plan -detailed-exitcode -var "new_relic_api_key=${{ secrets.NEW_RELIC_API_KEY }}" -var-file environments/${{ inputs.environment}}.tfvars -no-color $tfexitcode=$LASTEXITCODE Write-Output "Terraform exited with $tfexitcode" if ($tfexitcode -eq 2) { Write-Output "planHasChanges=true" >> "$GITHUB_OUTPUT" exit 0 } else { exit $tfexitcode } shell: pwsh working-directory: ${{ env.working_directory }}
内容的提问来源于stack exchange,提问作者kamilk
相关产品推荐
相关产品推荐

