Terraform配置:上传S3源桶无法触发CodePipeline问题排查
S3上传文件无法触发CodePipeline的问题修复
背景
我正在配置一套流水线:将Terraform代码打包为zip上传到S3源桶,触发CodePipeline执行terraform apply。已完成以下操作:
- 通过Terraform创建S3源桶
- 创建CodePipeline流水线
- 配置CloudWatch Events(EventBridge)规则监听S3事件
- 手动创建CloudTrail并添加数据事件记录源桶写入操作
但上传文件后流水线毫无反应。根据AWS文档描述,CloudTrail需要把过滤后的S3事件传给EventBridge规则,但控制台找不到相关配置入口。
AWS CloudTrail是用于记录并过滤Amazon S3源桶事件的服务,该跟踪会将过滤后的源变更发送至Amazon CloudWatch Events规则,由规则检测到变更后启动流水线。
现有配置代码
EventBridge规则
resource "aws_cloudwatch_event_rule" "xxxx-pipeline-event" { name = "xxxx-ci-cd-pipeline-event" description = "Cloud watch event when zip is uploaded to s3" event_pattern = <<EOF { "source": ["aws.s3"], "detail-type": ["AWS API Call via CloudTrail"], "detail": { "eventSource": ["s3.amazonaws.com"], "eventName": ["PutObject", "CompleteMultipartUpload", "CopyObject"], "requestParameters": { "bucketName": ["xxxxx-ci-cd-zip"], "key": ["app.zip"] } } } EOF } resource "aws_cloudwatch_event_target" "code-pipeline" { rule = aws_cloudwatch_event_rule.XXXX-pipeline-event.name target_id = "SendToCodePipeline" arn = aws_codepipeline.cicd_pipeline.arn role_arn = aws_iam_role.pipeline_role.arn }
EventBridge角色权限
data "aws_iam_policy_document" "event_bridge_role" { statement { actions = ["sts:AssumeRole"] effect = "Allow" principals { type = "Service" identifiers = ["events.amazonaws.com"] } } } resource "aws_iam_role" "pipeline_event_role" { name = "xxxxx-pipeline-event-bridge-role" assume_role_policy = data.aws_iam_policy_document.event_bridge_role.json } data "aws_iam_policy_document" "pipeline_event_role_policy" { statement { sid = "" actions = ["codepipeline:StartPipelineExecution"] resources = ["${aws_codepipeline.cicd_pipeline.arn}"] effect = "Allow" } } resource "aws_iam_policy" "pipeline_event_role_policy" { name = "xxxx-codepipeline-event-role-policy" policy = data.aws_iam_policy_document.pipeline_event_role_policy.json } resource "aws_iam_role_policy_attachment" "pipeline_event_role_attach_policy" { role = aws_iam_role.pipeline_event_role.name policy_arn = aws_iam_policy.pipeline_event_role_policy.arn }
问题根源与修复步骤
1. 致命错误:EventBridge目标角色引用错误
你创建了专门的EventBridge角色pipeline_event_role,但在aws_cloudwatch_event_target里却引用了pipeline_role.arn,导致EventBridge没有权限调用codepipeline:StartPipelineExecution接口。
修正后的目标配置:
resource "aws_cloudwatch_event_target" "code-pipeline" { rule = aws_cloudwatch_event_rule.xxxx-pipeline-event.name target_id = "SendToCodePipeline" arn = aws_codepipeline.cicd_pipeline.arn role_arn = aws_iam_role.pipeline_event_role.arn # 改为正确的角色ARN }
2. CloudTrail事件交付验证
CloudTrail默认会把事件传给EventBridge,但你需要确保:
- 创建CloudTrail时勾选了将事件发送到EventBridge(控制台在高级设置里;如果用Terraform,需确保
event_selectors正确包含S3数据事件,且CloudTrail的区域与EventBridge规则一致)。 - CloudTrail的数据事件选择器正确添加了目标S3桶的
PutObject/CompleteMultipartUpload/CopyObject操作,未排除相关事件。
3. 简化Event Pattern测试
当前的Event Pattern严格匹配key: app.zip,如果上传的文件路径或大小写有差异会导致匹配失败。先简化规则去掉key过滤,测试是否能触发:
{ "source": ["aws.s3"], "detail-type": ["AWS API Call via CloudTrail"], "detail": { "eventSource": ["s3.amazonaws.com"], "eventName": ["PutObject", "CompleteMultipartUpload", "CopyObject"], "requestParameters": { "bucketName": ["xxxxx-ci-cd-zip"] } } }
4. 事件链路验证
- 查看CloudTrail日志,确认目标S3操作事件已被记录。
- 在EventBridge规则的监控标签下查看匹配计数,确认是否有事件命中规则。
- 使用EventBridge的测试事件功能,模拟S3 PutObject事件,验证规则是否能触发流水线。
内容的提问来源于stack exchange,提问作者Jatin Mehrotra
相关产品推荐
相关产品推荐

