Tekton调试:When子句评估为false问题排查
问题:Tekton When子句未正确识别Task结果
我创建了一个用于检查Git仓库当前分支是否为发布分支的Tekton Task,配置如下:
apiVersion: tekton.dev/v1beta1 kind: Task metadata: name: check-git-remote-release-branches spec: params: - default: . description: The location of the root folder name: PATH_CONTEXT type: string - default: master description: Git reference name: GIT_REF type: string results: - description: true if release branch name: is-release-branch steps: - image: 'registry.redhat.io/rhel8/nodejs-16:latest' name: retrieving-remote-release-branches resources: {} script: > #!/bin/bash set -x git config --global --add safe.directory '*' git config --global user.email "git@48hg.ch" git config --global user.name "48hG - CICD" REMOTE_RELEASE_BRANCHES=($(git ls-remote --heads origin | grep release/ | awk '{print $2}')) echo "Current ref $(params.GIT_REF)" echo REMOTE_RELEASE_BRANCHES echo "false" | tee $(results.is-release-branch.path) for element in "${REMOTE_RELEASE_BRANCHES[@]}"; do echo "$element" if [[ $element == $(params.GIT_REF) ]]; then echo "true" | tee $(results.is-release-branch.path) fi done cat $(results.is-release-branch.path) workingDir: /workspace/source/$(params.PATH_CONTEXT) workspaces: - name: source
在Pipeline中调用该Task,将结果写入is-release-branch:
- name: check-git-remote-release-branches params: - name: PATH_CONTEXT value: $(params.context_path) - name: GIT_REF value: $(params.git-ref) runAfter: - continuous-integration-nodejs taskRef: kind: Task name: check-git-remote-release-branches workspaces: - name: source workspace: source-workspace
后续任务通过When子句判断结果:
- name: release-increase-version params: - name: PATH_CONTEXT value: $(params.context_path) runAfter: - check-git-remote-release-branches taskRef: kind: Task name: nodejs-release-commit when: - input: $(tasks.check-git-remote-release-branches.results.is-release-branch) operator: in values: - 'true'
尽管Task的结果文件中已写入true,但When子句始终不生效,请问如何调试该问题?是否有方法检查比较失败的原因?
调试与解决方案
1. 检查Task结果的实际内容(含隐藏字符)
Tekton的results会保留输出中的换行或空格,这是常见的匹配失败原因。通过以下命令查看结果原始内容:
- 获取TaskRun中结果的base64编码值:
kubectl get taskrun <你的TaskRun名称> -o jsonpath='{.status.results[?(@.name=="is-release-branch")].value}' - 解码并查看是否包含换行、空格等隐藏字符:
如果输出为kubectl get taskrun <你的TaskRun名称> -o jsonpath='{.status.results[?(@.name=="is-release-branch")].value}' | base64 -d | cat -Atrue$(带换行符),则When子句中的'true'无法匹配,因为实际值是true\n。
2. 修正Task脚本的结果输出
修改脚本中写入结果的逻辑,确保输出无多余字符:
- 使用
echo -n替代echo,避免自动添加换行符:echo -n "false" | tee $(results.is-release-branch.path) # 匹配成功时的输出 echo -n "true" | tee $(results.is-release-branch.path) - 或者通过
tr命令去除换行:echo "true" | tr -d '\n' | tee $(results.is-release-branch.path)
3. 验证GIT_REF的格式一致性
确认$(params.git-ref)传入的分支格式与git ls-remote返回的格式是否一致:
git ls-remote返回的分支是refs/heads/release/x.x.x格式,若你的GIT_REF仅传入release/x.x.x,会导致匹配失败。- 在Task脚本中添加日志,打印
GIT_REF的完整值:
若格式不匹配,需调整参数传入的值,或在脚本中统一格式(比如给echo "Full GIT_REF value: '$(params.GIT_REF)'"GIT_REF添加refs/heads/前缀)。
4. 查看PipelineRun的条件评估日志
查看PipelineRun的事件和状态,直接获取When条件的评估结果:
kubectl describe pipelinerun <你的PipelineRun名称>
在输出的Conditions或Events区域,会显示具体的匹配失败原因,比如Input: "true\n" does not match values: ["true"]。
5. 临时修改When条件测试
临时将in操作符替换为contains,验证是否为字符匹配问题:
when: - input: $(tasks.check-git-remote-release-branches.results.is-release-branch) operator: contains values: - 'true'
若此配置生效,说明结果中存在多余字符,需回到步骤1和2处理。
内容的提问来源于stack exchange,提问作者Otrebor
相关产品推荐
相关产品推荐

