如何在GitLab流水线后续阶段中使用Packer生成的AMI ID
问题
用户有一个基于Packer构建AMI镜像的GitLab流水线,希望在新增的test阶段中使用deploy阶段生成的AMI ID,但不知道如何捕获该输出值供后续步骤使用。尝试添加提取逻辑时,还遇到了jq: command not found的错误。
当前.gitlab-ci.yml配置
image: name: hashicorp/packer:latest entrypoint: - '/usr/bin/env' - 'PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin' before_script: - packer --version stages: - build - deploy get_packer: stage: build artifacts: paths: - packer script: - echo "Fetching packer" - wget https://releases.hashicorp.com/packer/1.5.5/packer_1.5.5_linux_amd64.zip - unzip packer_1.5.5_linux_amd64.zip - chmod +x packer deploy_packer: stage: deploy script: - echo "Deploying Packer Build" - cd aws - packer build -only="*rhel-stig*" .
流水线输出的AMI ID相关日志
Build 'rhel.amazon-ebs.rhel-stig' finished after 8 minutes 17 seconds. ==> Wait completed after 8 minutes 17 seconds ==> Builds finished. The artifacts of successful builds are: --> rhel.amazon-ebs.rhel-stig: AMIs were created: us-east-1: ami-08155b7eaa9e0274f Cleaning up project directory and file based variables 00:00 Job succeeded
用户期望的配置(新增test阶段)
image: name: hashicorp/packer:latest entrypoint: - '/usr/bin/env' - 'PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin' before_script: - packer --version stages: - build - deploy - test get_packer: stage: build artifacts: paths: - packer script: - echo "Fetching packer" - wget https://releases.hashicorp.com/packer/1.5.5/packer_1.5.5_linux_amd64.zip - unzip packer_1.5.5_linux_amd64.zip - chmod +x packer deploy_packer: stage: deploy script: - echo "Deploying Packer Build" - cd aws - packer build -only="*rhel-stig*" . test_image: stage: test script: - (Do something with the outputted AMI ID from the deploy stage)
尝试提取AMI ID时的错误日志
Build 'rhel.amazon-ebs.rhel-stig' finished after 9 minutes 22 seconds. ==> Wait completed after 9 minutes 22 seconds ==> Builds finished. The artifacts of successful builds are: --> rhel.amazon-ebs.rhel-stig: AMIs were created: us-east-1: ami-04b363eecd4fd841a --> rhel.amazon-ebs.rhel-stig: AMIs were created: us-east-1: ami-04b363eecd4fd841a $ AMI_ID=$(jq -r '.builds[-1].artifact_id' manifest.json | cut -d ":" -f2) /bin/bash: line 137: jq: command not found Uploading artifacts for failed job 00:00 Uploading artifacts... WARNING: image.env: no matching files. Ensure that the artifact path is relative to the working directory ERROR: No files to upload Cleaning up project directory and file based variables 00:01 ERROR: Job failed: exit code 1
解决方案
步骤1:捕获AMI ID并传递给后续阶段
hashicorp/packer:latest镜像默认未安装jq,可以选择以下两种可靠方式提取AMI ID,并通过GitLab的dotenv工件传递给test阶段:
方案A:安装jq,使用Packer Manifest文件(推荐)
Packer支持生成JSON格式的manifest文件,这种方式不受日志格式变化影响,稳定性更高。修改deploy_packer阶段:
deploy_packer: stage: deploy script: - echo "Deploying Packer Build" - cd aws # 安装jq(基于Alpine的Packer镜像用apk安装) - apk add --no-cache jq # 执行Packer构建并生成manifest文件 - packer build -only="*rhel-stig*" -manifest=manifest.json . # 提取AMI ID并写入环境变量文件 - AMI_ID=$(jq -r '.builds[-1].artifact_id' manifest.json | cut -d ":" -f2 | xargs) - echo "AMI_ID=$AMI_ID" > ../image.env # 将环境变量文件作为dotenv工件传递,GitLab会自动注入到后续阶段 artifacts: reports: dotenv: image.env
方案B:无需jq,直接从日志提取
如果不想安装额外工具,可通过grep+awk从Packer输出中提取AMI ID:
deploy_packer: stage: deploy script: - echo "Deploying Packer Build" - cd aws # 执行构建并保存日志,避免输出丢失 - packer build -only="*rhel-stig*" . | tee build.log # 提取最后出现的AMI ID - AMI_ID=$(grep -o 'ami-[a-f0-9]*' build.log | tail -n1) - echo "AMI_ID=$AMI_ID" > ../image.env artifacts: reports: dotenv: image.env
步骤2:在test阶段使用AMI ID
修改test_image阶段,直接使用GitLab自动注入的AMI_ID环境变量:
test_image: stage: test script: - echo "开始测试AMI: $AMI_ID" # 在此添加你的测试逻辑,例如启动EC2实例验证镜像可用性、执行合规检查等
内容的提问来源于stack exchange,提问作者Mitchell Privett
相关产品推荐
相关产品推荐

