You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

多作业场景下如何通过GitHub Actions用kustomize edit更新镜像

解决Kustomize多应用镜像冲突的配置方案

核心问题原因

你当前的问题是两个CI作业使用了同一个镜像占位符(gcr.io/PROJECT_ID/IMAGE:TAG),导致kustomize edit set image命令会互相覆盖对方的镜像配置,最终两个应用指向同一镜像。

解决方案步骤

1. 调整kustomization.yaml的镜像配置

首先给两个应用的镜像分别设置独立的占位符名称:

  • 在Identity应用的Deployment(或其他资源文件)中,将镜像字段改为identity-image:latest
  • 在API应用的Deployment中,将镜像字段改为api-image:latest

然后在根目录的kustomization.yaml里,为这两个占位符配置初始映射:

resources:
  - ./identity/deployment.yaml
  - ./api/deployment.yaml

images:
  - name: identity-image
    newName: gcr.io/PROJECT_ID/identity-image
    newTag: latest
  - name: api-image
    newName: gcr.io/PROJECT_ID/api-image
    newTag: latest

2. 修改GitHub Actions作业中的kustomize命令

分别针对各自的镜像占位符执行修改操作,避免互相覆盖:

Identity作业命令

./kustomize edit set image identity-image=gcr.io/$PROJECT_ID/$IDSIMAGE:$GITHUB_SHA
./kustomize build . | kubectl apply -f -

API作业命令

./kustomize edit set image api-image=gcr.io/$PROJECT_ID/$APIIMAGE:$GITHUB_SHA
./kustomize build . | kubectl apply -f -

3. 额外优化建议

如果仓库允许,建议给每个应用单独创建kustomize子目录(比如k8s/identity和k8s/api),各自维护独立的kustomization.yaml,这样CI作业可以直接在对应目录下执行命令,彻底避免配置冲突:

  • Identity作业:cd k8s/identity && ./kustomize edit set image ...
  • API作业:cd k8s/api && ./kustomize edit set image ...

内容的提问来源于stack exchange,提问作者Hakeem Oriola

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 13:12:51