如何在第二代Cloud Function中使用内部BitBucket仓库作为代码源(Terraform)
解决方案:Terraform部署第二代Cloud Function对接内部BitBucket仓库
核心结论
直接通过google_cloudfunctions2_function的repo_source参数无法对接内部BitBucket仓库——该参数仅原生支持Cloud Source Repositories(GCSR)和已通过Cloud Build授权的GitHub仓库,BitBucket(包括内部托管版)不在官方支持的repo源列表中。
可行替代方案
以下两种方案均可实现需求,同时支持指定源码在仓库中的存储目录:
方案1:本地拉取BitBucket代码+Terraform打包上传GCS部署
适合CI/CD流程中已包含代码拉取步骤的场景,直接在Terraform中处理源码打包与上传:
- 打包指定目录的源码
使用archive_file数据源,指定BitBucket仓库中存放函数代码的目录(本地拉取后的路径):
data "archive_file" "function_source" { type = "zip" source_dir = "./local-bitbucket-repo/function-code-dir" # 替换为本地拉取后的函数源码目录 output_path = "./function-source.zip" }
- 上传源码包到GCS
创建GCS桶并上传打包后的zip文件:
resource "google_storage_bucket" "function_source_bucket" { name = "your-unique-bucket-name" # 需全局唯一 location = "us-central1" # 与Cloud Function地域保持一致 } resource "google_storage_bucket_object" "function_zip" { name = "function-source.zip" bucket = google_storage_bucket.function_source_bucket.name source = data.archive_file.function_source.output_path }
- 部署第二代Cloud Function
通过storage_source参数引用GCS中的源码包:
resource "google_cloudfunctions2_function" "my_function" { name = "your-function-name" location = "us-central1" description = "Second-gen function from internal BitBucket repo" build_config { runtime = "nodejs20" # 替换为你的函数运行时 entry_point = "helloWorld" # 替换为你的函数入口 storage_source { bucket = google_storage_bucket.function_source_bucket.name object = google_storage_bucket_object.function_zip.name } } service_config { available_memory = "256MiB" timeout_seconds = 60 } }
方案2:Cloud Build拉取BitBucket代码+上传GCS部署
适合需要完全在云端完成源码拉取与打包的场景,需配合Cloud Build触发器:
- 配置Cloud Build拉取内部BitBucket代码
- 为Cloud Build服务账号配置BitBucket拉取权限(如添加SSH密钥到BitBucket仓库)
- 创建Cloud Build构建逻辑,指定拉取仓库、进入目标目录并打包上传到GCS:
resource "google_cloudbuild_trigger" "bitbucket_sync" { name = "bitbucket-function-source-sync" description = "Pull and package code from internal BitBucket" trigger_template { branch_name = "main" # 替换为你的目标分支 } build { steps { name = "gcr.io/cloud-builders/git" args = ["clone", "git@your-internal-bitbucket:team/repo.git", "."] } steps { name = "gcr.io/cloud-builders/zip" args = ["-r", "function-source.zip", "./function-code-dir"] # 指定仓库中的源码目录 } steps { name = "gcr.io/cloud-builders/gsutil" args = ["cp", "function-source.zip", "gs://${google_storage_bucket.function_source_bucket.name}/"] } } }
- 触发构建并部署函数
通过null_resource触发Cloud Build构建,再引用GCS中的源码包部署函数:
# 触发Cloud Build构建 resource "null_resource" "trigger_build" { provisioner "local-exec" { command = "gcloud builds submit --trigger=${google_cloudbuild_trigger.bitbucket_sync.name}" } depends_on = [google_storage_bucket.function_source_bucket] } # 部署Cloud Function resource "google_cloudfunctions2_function" "my_function" { name = "your-function-name" location = "us-central1" description = "Second-gen function via Cloud Build + BitBucket" build_config { runtime = "nodejs20" entry_point = "helloWorld" storage_source { bucket = google_storage_bucket.function_source_bucket.name object = "function-source.zip" } } service_config { available_memory = "256MiB" timeout_seconds = 60 } depends_on = [null_resource.trigger_build] }
注意事项
- 确保相关服务账号具备对应权限:Cloud Build服务账号需有BitBucket拉取权限、GCS写入权限;Cloud Functions服务账号需有GCS读取权限。
- 内部BitBucket仓库若需VPN访问,需配置Cloud Build使用私有网络或VPN连接。
内容的提问来源于stack exchange,提问作者Kara
相关产品推荐
相关产品推荐

