Bitbucket流水线部署AWS CloudFormation时出现报错求助
AWS CloudFormation Bitbucket流水线部署失败排查
问题详情
本地通过samconfig.toml配置部署AWS CloudFormation完全正常,但在Bitbucket流水线中执行部署时失败。流水线步骤配置如下:
step: name: Deploy to Cloudformation script: - pipe: atlassian/aws-sam-deploy:1.1.0 variables: AWS_ACCESS_KEY_ID: 'my id here' AWS_SECRET_ACCESS_KEY: 'key here' AWS_SESSION_TOKEN: 'sessionToken' AWS_DEFAULT_REGION: 'us-east-1' S3_BUCKET: 's3bucketname' STACK_NAME: 'stackname' s3_prefix: 'stackname' SAM_TEMPLATE: 'template.yaml' capabilities: ['CAPABILITY_NAMED_IAM', 'CAPABILITY_AUTO_EXPAND'] parameter_overrides: ["VPC=\"vpcenteredhere\" VPCEName=\"vpceenteredhere\" MyStageName=\"test\" ApplicationTag=\"project\""]
部署触发的错误信息:
✖ Failed to create the stack. An error occurred (InsufficientCapabilitiesException) when calling the CreateStack operation: Requires capabilities : [CAPABILITY_AUTO_EXPAND] ERROR: Failed to get information about stack stackname. An error occurred (ValidationError) when calling the DescribeStacks operation: Stack with id stackname does not exist
解决方法
修正capabilities参数格式
旧版本的Atlassian SAM部署管道对数组格式的capabilities解析存在问题,直接用空格分隔的字符串传递即可:capabilities: 'CAPABILITY_NAMED_IAM CAPABILITY_AUTO_EXPAND'调整parameter_overrides的传递方式
当前把所有参数塞在一个字符串里容易出现解析错误,改成逐个参数单独传递:parameter_overrides: - 'VPC="vpcenteredhere"' - 'VPCEName="vpceenteredhere"' - 'MyStageName="test"' - 'ApplicationTag="project"'升级SAM部署管道版本
你用的atlassian/aws-sam-deploy:1.1.0版本太老,参数处理逻辑存在bug,直接升级到最新稳定版(比如3.x系列),能避免很多兼容性问题。确认模板嵌套栈配置
既然报错要求CAPABILITY_AUTO_EXPAND,说明你的模板里包含嵌套栈资源,必须确保这个权限被正确传递给CloudFormation,本地正常是因为samconfig.toml里已经配置了该参数,流水线里不能遗漏。
内容的提问来源于stack exchange,提问作者Tanu
相关产品推荐
相关产品推荐

