You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Action中Terraform -detailed-exitcode参数无法正常生效

Terraform Plan -detailed-exitcode在GitHub Actions中返回码异常问题

Terraform的terraform plan -detailed-exitcode参数,在命令执行成功且存在资源差异时应返回退出码2。但在GitHub工作流中使用hashicorp/setup-terraform action执行该命令时,即便存在资源变更(如示例中的新建告警策略),退出码仍为0;本地手动执行则正常返回退出码2。尝试过Bash和PowerShell两种脚本写法,问题依旧。

GitHub工作流配置

name: 'Terraform: Main'
on:
  workflow_call:
    inputs:
      environment:
        required: true
        type: string

permissions:
  contents: read
  id-token: write
  pull-requests: write

env:
  working_directory: ./terraform

jobs:
  terraform_check_changes:
    runs-on: ubuntu-latest
    environment: ${{ inputs.environment }}
    steps:

    - name: Checkout Repository
      uses: actions/checkout@v3

    - name: "Terraform: Setup"
      uses: hashicorp/setup-terraform@v2
      with:
        terraform_version:  1.6.0

    - name: "Terraform: Init"
      id: init
      run: terraform init -backend-config use_azuread_auth=false -backend-config use_oidc=true
      shell: bash
      working-directory: ${{ env.working_directory }}
      env:
        ARM_CLIENT_ID:  ${{ vars.AZURE_CLIENT_ID }}

    - name: "Terraform: Plan"
      id: plan
      run: |
        set +e
        terraform plan -var "new_relic_api_key=${{ secrets.NEW_RELIC_API_KEY }}" -var-file environments/${{ inputs.environment}}.tfvars -no-color -detailed-exitcode
        exitcode=$?
        echo "Terraform exited with $exitcode"
        if [[ $exitcode -eq 2 ]]; then
          echo "planHasChanges=true" >> "$GITHUB_OUTPUT"
          exit 0
        else
          exit $exitcode
        fi
      shell: bash
      working-directory: ${{ env.working_directory }}
      env:
        ARM_CLIENT_ID:  ${{ vars.AZURE_CLIENT_ID }}

Plan步骤执行输出

/home/runner/work/_temp/9efc414b-0934-467d-902b-9926937a2e8f/terraform-bin plan -var new_relic_api_key=*** -var-file environments/dev.tfvars -no-color -detailed-exitcode

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create

Terraform will perform the following actions:

  # newrelic_alert_policy.kamil_test_policy will be created
  + resource "newrelic_alert_policy" "kamil_test_policy" {
      + account_id          = (known after apply)
      + id                  = (known after apply)
      + incident_preference = "PER_POLICY"
      + name                = "Kamil's Terraform test"
    }

Plan: 1 to add, 0 to change, 0 to destroy.

─────────────────────────────────────────────────────────────────────────────

Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
Terraform exited with 0

尝试的PowerShell脚本

- name: "Terraform: Plan"
      id: plan
      run: |
        terraform plan -detailed-exitcode -var "new_relic_api_key=${{ secrets.NEW_RELIC_API_KEY }}" -var-file environments/${{ inputs.environment}}.tfvars -no-color
        $tfexitcode=$LASTEXITCODE
        Write-Output "Terraform exited with $tfexitcode"
        if ($tfexitcode -eq 2) {
          Write-Output "planHasChanges=true" >> "$GITHUB_OUTPUT"
          exit 0
        } else {
          exit $tfexitcode
        }
      shell: pwsh
      working-directory: ${{ env.working_directory }}

内容的提问来源于stack exchange,提问作者kamilk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 13:52:48