You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

多目录仓库下基于GCP与GitHub Actions的Terraform CI/CD配置问题

解决多目录仓库中GitHub Actions执行Terraform的问题

问题分析

你遇到的核心矛盾是:切换到terraform目录执行Terraform命令时,GCP凭证无法被识别;不切换目录则找不到Terraform配置文件。本质是工作目录切换后,GCP认证环境变量的传递或凭证文件的访问出现异常,而Terraform需要明确的配置文件路径。

可行解决方案

方案一:使用Terraform的-chdir参数(推荐)

无需切换全局工作目录,直接在Terraform命令中指定配置文件所在目录。这种方式既能让Terraform找到配置文件,又能保留根目录下设置的GCP认证环境变量,完美规避两个问题。

修改后的GitHub Actions配置如下:

name: 'Terraform'

on: [push]

permissions:
  contents: read

jobs:
  terraform:
    name: 'Terraform'      
    runs-on: ubuntu-latest
    environment: production

    defaults:
      run:
        shell: bash

    steps:
    - name: Checkout
      uses: actions/checkout@v3

    - name: Setup Terraform
      uses: hashicorp/setup-terraform@v1
      
    - id: 'auth'
      uses: 'google-github-actions/auth@v1'
      with:
        credentials_json: '${{ secrets.GCP_CREDENTIALS }}'

    - name: 'Set up Cloud SDK'
      uses: 'google-github-actions/setup-gcloud@v1'

    - name: Terraform Init
      run: terraform -chdir=terraform init

    - name: Terraform Format
      run: terraform -chdir=terraform fmt -check

    - name: Terraform Apply
      run: terraform -chdir=terraform apply -auto-approve -input=false

方案二:全局切换工作目录并验证凭证环境变量

如果坚持使用working-directory配置,需要确保GCP认证的环境变量在子目录中正常生效。可以添加步骤验证环境变量,同时确保凭证文件路径正确:

name: 'Terraform'

on: [push]

permissions:
  contents: read

jobs:
  terraform:
    name: 'Terraform'      
    runs-on: ubuntu-latest
    environment: production

    defaults:
      run:
        shell: bash
        working-directory: terraform

    steps:
    - name: Checkout
      uses: actions/checkout@v3

    - name: Setup Terraform
      uses: hashicorp/setup-terraform@v1
      
    - id: 'auth'
      uses: 'google-github-actions/auth@v1'
      with:
        credentials_json: '${{ secrets.GCP_CREDENTIALS }}'

    - name: 'Set up Cloud SDK'
      uses: 'google-github-actions/setup-gcloud@v1'

    # 验证GCP凭证环境变量是否存在
    - name: Verify GCP Credentials Env Var
      run: echo $GOOGLE_APPLICATION_CREDENTIALS

    - name: Terraform Init
      run: terraform init

    - name: Terraform Format
      run: terraform fmt -check

    - name: Terraform Apply
      run: terraform apply -auto-approve -input=false

如果验证步骤显示GOOGLE_APPLICATION_CREDENTIALS存在但仍报错,可手动指定Terraform的GCP provider凭证路径(在Terraform配置文件中添加):

provider "google" {
  credentials = file(var.credentials_path)
  # 其他配置...
}

并在GitHub Actions中传递凭证路径变量:

- name: Terraform Init
  run: terraform init -var credentials_path=${{ env.GOOGLE_APPLICATION_CREDENTIALS }}

方案选择建议

优先使用方案一,因为它不需要修改Terraform配置,也无需额外的环境变量验证,是最简洁可靠的解决方式。

内容的提问来源于stack exchange,提问作者itasahobby

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 13:40:57