You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在第二代Cloud Function中使用内部BitBucket仓库作为代码源(Terraform)

解决方案:Terraform部署第二代Cloud Function对接内部BitBucket仓库

核心结论

直接通过google_cloudfunctions2_function的repo_source参数无法对接内部BitBucket仓库——该参数仅原生支持Cloud Source Repositories(GCSR)和已通过Cloud Build授权的GitHub仓库,BitBucket(包括内部托管版)不在官方支持的repo源列表中。

可行替代方案

以下两种方案均可实现需求,同时支持指定源码在仓库中的存储目录:


方案1:本地拉取BitBucket代码+Terraform打包上传GCS部署

适合CI/CD流程中已包含代码拉取步骤的场景,直接在Terraform中处理源码打包与上传:

  1. 打包指定目录的源码
    使用archive_file数据源,指定BitBucket仓库中存放函数代码的目录(本地拉取后的路径):
data "archive_file" "function_source" {
  type        = "zip"
  source_dir  = "./local-bitbucket-repo/function-code-dir" # 替换为本地拉取后的函数源码目录
  output_path = "./function-source.zip"
}
  1. 上传源码包到GCS
    创建GCS桶并上传打包后的zip文件:
resource "google_storage_bucket" "function_source_bucket" {
  name     = "your-unique-bucket-name" # 需全局唯一
  location = "us-central1" # 与Cloud Function地域保持一致
}

resource "google_storage_bucket_object" "function_zip" {
  name   = "function-source.zip"
  bucket = google_storage_bucket.function_source_bucket.name
  source = data.archive_file.function_source.output_path
}
  1. 部署第二代Cloud Function
    通过storage_source参数引用GCS中的源码包:
resource "google_cloudfunctions2_function" "my_function" {
  name        = "your-function-name"
  location    = "us-central1"
  description = "Second-gen function from internal BitBucket repo"

  build_config {
    runtime     = "nodejs20" # 替换为你的函数运行时
    entry_point = "helloWorld" # 替换为你的函数入口
    storage_source {
      bucket = google_storage_bucket.function_source_bucket.name
      object = google_storage_bucket_object.function_zip.name
    }
  }

  service_config {
    available_memory = "256MiB"
    timeout_seconds  = 60
  }
}

方案2:Cloud Build拉取BitBucket代码+上传GCS部署

适合需要完全在云端完成源码拉取与打包的场景,需配合Cloud Build触发器:

  1. 配置Cloud Build拉取内部BitBucket代码
  • 为Cloud Build服务账号配置BitBucket拉取权限(如添加SSH密钥到BitBucket仓库)
  • 创建Cloud Build构建逻辑,指定拉取仓库、进入目标目录并打包上传到GCS:
resource "google_cloudbuild_trigger" "bitbucket_sync" {
  name        = "bitbucket-function-source-sync"
  description = "Pull and package code from internal BitBucket"
  trigger_template {
    branch_name = "main" # 替换为你的目标分支
  }
  build {
    steps {
      name = "gcr.io/cloud-builders/git"
      args = ["clone", "git@your-internal-bitbucket:team/repo.git", "."]
    }
    steps {
      name = "gcr.io/cloud-builders/zip"
      args = ["-r", "function-source.zip", "./function-code-dir"] # 指定仓库中的源码目录
    }
    steps {
      name = "gcr.io/cloud-builders/gsutil"
      args = ["cp", "function-source.zip", "gs://${google_storage_bucket.function_source_bucket.name}/"]
    }
  }
}
  1. 触发构建并部署函数
    通过null_resource触发Cloud Build构建,再引用GCS中的源码包部署函数:
# 触发Cloud Build构建
resource "null_resource" "trigger_build" {
  provisioner "local-exec" {
    command = "gcloud builds submit --trigger=${google_cloudbuild_trigger.bitbucket_sync.name}"
  }
  depends_on = [google_storage_bucket.function_source_bucket]
}

# 部署Cloud Function
resource "google_cloudfunctions2_function" "my_function" {
  name        = "your-function-name"
  location    = "us-central1"
  description = "Second-gen function via Cloud Build + BitBucket"

  build_config {
    runtime     = "nodejs20"
    entry_point = "helloWorld"
    storage_source {
      bucket = google_storage_bucket.function_source_bucket.name
      object = "function-source.zip"
    }
  }

  service_config {
    available_memory = "256MiB"
    timeout_seconds  = 60
  }

  depends_on = [null_resource.trigger_build]
}

注意事项

  • 确保相关服务账号具备对应权限:Cloud Build服务账号需有BitBucket拉取权限、GCS写入权限;Cloud Functions服务账号需有GCS读取权限。
  • 内部BitBucket仓库若需VPN访问,需配置Cloud Build使用私有网络或VPN连接。

内容的提问来源于stack exchange,提问作者Kara

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 03:13:22