如何用Terraform拉取ECR镜像,镜像不存在时设置默认值
解决办法
核心思路是避免ECR无镜像时触发aws_ecr_image数据源报错,通过条件控制数据源实例化,同时预留默认标签值。
方案1:用count控制数据源创建
通过aws_ecr_repository查询仓库镜像清单,判断是否存在镜像,仅当有镜像时才实例化aws_ecr_image数据源,无镜像时直接使用默认的latest标签。
# 查询ECR仓库基本信息,包含镜像ID列表 data "aws_ecr_repository" "repo" { name = module.ecr.repository_name } # 仅当仓库存在镜像时创建该数据源 data "aws_ecr_image" "image" { count = length(data.aws_ecr_repository.repo.image_ids) > 0 ? 1 : 0 repository_name = module.ecr.repository_name image_tag = "latest" depends_on = [module.ecr] } module "container_definition" { source = "cloudposse/ecs-container-definition/aws" version = "0.58.1" container_name = local.container_name # 数据源存在则取哈希标签,否则用latest container_image = format( "%s.dkr.ecr.%s.amazonaws.com/%s:%s", module.global_settings.aws_account_id, module.global_settings.region, local.project_name, length(data.aws_ecr_image.image) > 0 ? try(data.aws_ecr_image.image[0].image_tags[1], "latest") : "latest" ) container_memory = local.memory container_memory_reservation = local.memory_reservarion container_cpu = local.cpu essential = local.essential readonly_root_filesystem = local.readonly_root_system environment = local.task_environment_variables secrets = local.task_environment_secret_variables port_mappings = local.port_mappings log_configuration = local.container_log_configuration depends_on = [module.ecr] }
关键说明
- 利用
length(data.aws_ecr_repository.repo.image_ids)判断仓库是否有镜像,通过count控制aws_ecr_image数据源的创建,彻底避免无镜像时的数据源报错。 try(data.aws_ecr_image.image[0].image_tags[1], "latest")用于兼容镜像仅存在latest单标签的场景,防止索引越界报错。- 无镜像时硬编码使用
latest,符合后续流水线推送镜像后服务可正常启动的需求。
内容的提问来源于stack exchange,提问作者Math.Random
相关产品推荐
相关产品推荐

