GitLab CI执行CloudFormation部署失败,本地运行正常
GitLab CI自动化部署CloudFormation报错解决
问题详情
本地执行以下AWS CLI部署命令完全正常,但在GitLab CI Runner环境中运行时抛出异常:
aws --region us-east-1 cloudformation deploy --parameter-overrides file://aws/templates/STAG/us-east-1/us-east-1-1.json --template-file aws/templates/tenable_template.yaml --stack-name STAG-us-east-1-1
参数文件us-east-1-1.json内容:
{ "Parameters": { "TenableName": "STAG-USE1-vpc-066511axxxxd4", "VpcId": "vpc-066511axxxxd4", "ELBSubnets": "subnet-054adxxxxx9c7,subnet-0f47axxxxac52cd", "Location": "USE1", "EnvironmentType": "staging" } }
报错信息:
[u'{'] value passed to --parameter-overrides must be of format Key=Value
报错原因
报错说明CI环境中AWS CLI未能正确解析file://指向的JSON参数文件,反而将文件内容的起始字符{当作直接传入的参数值,不符合Key=Value的参数格式要求。[u'{']中的u是Python Unicode字符串标识,通常出现在较旧版本的AWS CLI环境中,或是CI的Shell环境对路径解析逻辑与本地不同。
解决方案
1. 升级AWS CLI版本
旧版本的aws cloudformation deploy不支持file://方式加载参数文件(该特性从AWS CLI 1.16.10版本开始支持)。先在CI环境中检查当前版本:
aws --version
如果版本低于要求,执行对应系统的升级命令,例如:
- Ubuntu/Debian:
apt-get update && apt-get install -y awscli - RHEL/CentOS:
yum update -y awscli - 使用pip:
pip install --upgrade awscli
2. 使用绝对路径指向参数文件
CI环境的工作目录可能与本地不同,相对路径无法被正确识别。可以先获取项目根目录的绝对路径,再拼接参数文件路径:
PARAM_FILE=$(pwd)/aws/templates/STAG/us-east-1/us-east-1-1.json aws --region us-east-1 cloudformation deploy --parameter-overrides file://$PARAM_FILE --template-file aws/templates/tenable_template.yaml --stack-name STAG-us-east-1-1
3. 转换JSON参数为Key=Value格式
如果无法升级CLI,可借助jq工具将JSON参数转换为Key=Value格式直接传入:
# 先确保CI环境已安装jq,若未安装需先执行安装命令(如apt-get install jq) PARAMS=$(jq -r '.Parameters | to_entries | .[] | "\(.key)=\(.value)"' aws/templates/STAG/us-east-1/us-east-1-1.json) aws --region us-east-1 cloudformation deploy --parameter-overrides $PARAMS --template-file aws/templates/tenable_template.yaml --stack-name STAG-us-east-1-1
4. 统一Shell环境
本地可能使用Bash,而CI Runner默认使用Sh,二者语法解析存在差异。可在CI配置中指定使用Bash执行脚本:
# .gitlab-ci.yml示例 deploy: script: - bash deploy_script.sh # 或者直接指定shell shell: bash
内容的提问来源于stack exchange,提问作者Juan.
相关产品推荐
相关产品推荐

