You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Terraform配置以Cloud Function为目标的Eventarc触发器

解答

全Terraform部署方案存在,无需依赖GUI

完全可以通过Terraform完成Eventarc触发器+Cloud Function的全量部署,不需要先部署函数再通过GUI配置。有两种可行方案:


方案1:在Cloud Function资源中直接配置event_trigger块

你的思路是对的,但猜测代码里有几个参数错误,修正后的示例如下:

resource "google_cloudfunctions_function" "cloudfunc-name" {
  name                  = "cloudfunc-name"
  description           = "cloud func desc"
  runtime               = "python39"
  project               = "googleproject"
  region                = "us-central1"
  available_memory_mb   = 256
  max_instances         = 10
  timeout               = 300
  entry_point           = "helloworld_entry"
  source_archive_bucket = "your-bucket-name" # 此处填存储代码包的GCS桶名,而非文件路径
  source_archive_object = google_storage_bucket_object.function_zip_bucket_object.name

  event_trigger {
    event_type = "google.cloud.audit.log.v1.written"
    # 用filter指定具体的BigQuery操作
    filter = "protoPayload.methodName=\"google.cloud.bigquery.v2.TableService.InsertTable\""
    # 指定生成审计日志的服务
    service = "bigquery.googleapis.com"
    # 触发函数使用的服务账号,可省略(默认用函数的默认服务账号)
    service_account = "someserviceaccount@gserviceaccount.com"
    failure_policy {
      retry = false
    }
  }
}

核心修正点:

  • source_archive_bucket 需填写存储代码ZIP包的GCS桶名称,不是文件路径
  • 审计日志事件无需event或receive_event参数,改用filter和service定位具体事件

方案2:使用独立的Eventarc触发器资源(推荐)

如果需要更复杂的配置(比如多触发器指向同一函数、自定义事件路由),推荐用google_eventarc_trigger资源单独管理触发器,实现函数与触发器的解耦:

# 先部署Cloud Function
resource "google_cloudfunctions_function" "cloudfunc-name" {
  name                  = "cloudfunc-name"
  description           = "cloud func desc"
  runtime               = "python39"
  project               = "googleproject"
  region                = "us-central1"
  available_memory_mb   = 256
  max_instances         = 10
  timeout               = 300
  entry_point           = "helloworld_entry"
  source_archive_bucket = "your-bucket-name"
  source_archive_object = google_storage_bucket_object.function_zip_bucket_object.name
}

# 部署指向该Cloud Function的Eventarc触发器
resource "google_eventarc_trigger" "cf-trigger" {
  name        = "cf-bigquery-trigger"
  project     = "googleproject"
  region      = "us-central1"
  destination {
    cloud_function {
      function = google_cloudfunctions_function.cloudfunc-name.name
    }
  }

  event_filters {
    attribute = "type"
    value     = "google.cloud.audit.log.v1.written"
  }

  event_filters {
    attribute = "serviceName"
    value     = "bigquery.googleapis.com"
  }

  event_filters {
    attribute = "methodName"
    value     = "google.cloud.bigquery.v2.TableService.InsertTable"
  }

  service_account = "someserviceaccount@gserviceaccount.com"

  failure_policy {
    retry = false
  }
}

这种方式更符合基础设施即代码的模块化原则,后续修改触发器规则无需改动函数配置。

内容的提问来源于stack exchange,提问作者Henry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 02:40:40