测试阶段如何在Atlantis中忽略Conftest策略检查失败以合并PR?
问题:测试阶段如何绕过Policy Check失败强制合并PR
我正处于测试阶段,希望即使policy_check失败也允许合并我的PR,请问可以传递什么标志来实现该需求?
当前Atlantis配置
repos: - id: /.*/ workflow: custom apply_requirements: [mergeable] allow_custom_workflows: true allowed_overrides: [apply_requirements, workflow] policies: owners: users: - XXX policy_sets: - name: conftest path: /atlantis/conftest_policies/policies/ source: local workflows: custom: plan: steps: - init - plan policy_check: steps: - show - policy_check: extra_args: ["--update", "git::https://${serviceVariable.SAMPLE_TOKEN}@github.com/Company/conftest-policy.git", "--all-namespaces" ]
Atlantis Plan执行输出
exit status 1 Checking plan against the following policies: conftest ? - <redacted plan file> - gcp.common - no policies found FAIL - <redacted plan file> - gcp.iam - Service Account User and Service Account Token Creator roles are prohibited at the project level and must be assigned to specific service accounts. service_account_iam_roles uses the role roles/iam.serviceAccountUser. 38 tests, 36 passed, 1 warning, 1 failure, 0 exceptions
解决方案
你可以通过以下方式实现测试阶段绕过Policy Check失败的限制:
方式1:命令行标志临时跳过(推荐)
在PR的Atlantis评论中执行命令时,添加--skip-policy-checks标志,即可直接跳过policy_check步骤,即使规则校验失败也能继续执行后续操作:
- 执行Plan:
atlantis plan --skip-policy-checks - 执行Apply:
atlantis apply --skip-policy-checks
方式2:配置覆盖临时调整(适合长期测试场景)
利用配置中allowed_overrides包含apply_requirements和workflow的特性,也可以在PR评论中覆盖配置:
- 临时清空合并要求:
atlantis plan --override apply_requirements=[] - 或者指定一个不含policy_check步骤的自定义Workflow(需提前在Atlantis配置中定义):
atlantis plan --override workflow=test-skip-policy
注意:以上方法仅适合测试阶段临时使用,正式环境请严格遵循Policy Check规则保障合规性。
内容的提问来源于stack exchange,提问作者chan214
相关产品推荐
相关产品推荐

