如何通过Terraform的helm_release在YAML中设置字符串列表键值
解决Terraform helm_release配置ArgoCD SSO requestedScopes单行列表问题
核心问题原因
当在Terraform的helm_release资源中用嵌套Map结构定义ArgoCD的oidc.config时,Terraform会自动将列表类型的requestedScopes序列化为多行YAML格式。而ArgoCD的argocd-cm ConfigMap中,oidc.config是一个完整的YAML字符串,我们可以通过直接构造该字符串来精确控制格式。
解决方案1:使用Heredoc直接构造单行列表
直接在oidc.config的字符串中写入单行格式的requestedScopes:
resource "helm_release" "argocd" { name = "argocd" repository = "https://argoproj.github.io/argo-helm" chart = "argo-cd" version = "5.45.0" # 替换为你使用的ArgoCD Helm Chart版本 values = [ yamlencode({ configs = { cm = { "argocd-cm" = { oidc.config = <<EOT name: MyOIDC issuer: https://your-oidc-issuer.com clientID: your-client-id clientSecret: your-client-secret requestedScopes: ["openid", "profile", "email", "groups"] EOT } } } }) ] }
这种方式下,Heredoc中的requestedScopes行保持单行,最终生成的ConfigMap中oidc.config的对应值会完整保留该格式。
解决方案2:使用模板文件+yamlencode函数(动态场景)
如果需要动态生成requestedScopes列表,可结合Terraform的templatefile和yamlencode函数实现:
- 创建模板文件
oidc_config.tpl:
name: ${name} issuer: ${issuer} clientID: ${client_id} clientSecret: ${client_secret} requestedScopes: ${requested_scopes}
- 在Terraform配置中引用该模板:
locals { oidc_scopes = ["openid", "profile", "email", "groups"] } resource "helm_release" "argocd" { name = "argocd" repository = "https://argoproj.github.io/argo-helm" chart = "argo-cd" version = "5.45.0" values = [ yamlencode({ configs = { cm = { "argocd-cm" = { oidc.config = templatefile("${path.module}/oidc_config.tpl", { name = "MyOIDC" issuer = "https://your-oidc-issuer.com" client_id = "your-client-id" client_secret = "your-client-secret" requested_scopes = yamlencode(local.oidc_scopes) }) } } } }) ] }
yamlencode(local.oidc_scopes)会将列表序列化为单行的["openid", "profile", "email", "groups"]字符串,插入模板后即可得到符合要求的格式。
验证方法
应用配置后,通过以下命令查看生成的ConfigMap内容,确认requestedScopes为单行格式:
kubectl get configmap argocd-cm -n argocd -o yaml
在输出的data.oidc.config中,应能看到:
requestedScopes: ["openid", "profile", "email", "groups"]
内容的提问来源于stack exchange,提问作者cypherphage
相关产品推荐
相关产品推荐

