You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置:上传S3源桶无法触发CodePipeline问题排查

S3上传文件无法触发CodePipeline的问题修复

背景

我正在配置一套流水线:将Terraform代码打包为zip上传到S3源桶,触发CodePipeline执行terraform apply。已完成以下操作:

  • 通过Terraform创建S3源桶
  • 创建CodePipeline流水线
  • 配置CloudWatch Events(EventBridge)规则监听S3事件
  • 手动创建CloudTrail并添加数据事件记录源桶写入操作

但上传文件后流水线毫无反应。根据AWS文档描述,CloudTrail需要把过滤后的S3事件传给EventBridge规则,但控制台找不到相关配置入口。

AWS CloudTrail是用于记录并过滤Amazon S3源桶事件的服务,该跟踪会将过滤后的源变更发送至Amazon CloudWatch Events规则,由规则检测到变更后启动流水线。

现有配置代码

EventBridge规则

resource "aws_cloudwatch_event_rule" "xxxx-pipeline-event" {
  name        = "xxxx-ci-cd-pipeline-event"
  description = "Cloud watch event when zip is uploaded to s3"

  event_pattern = <<EOF
{
  "source": ["aws.s3"],
  "detail-type": ["AWS API Call via CloudTrail"],
  "detail": {
    "eventSource": ["s3.amazonaws.com"],
    "eventName": ["PutObject", "CompleteMultipartUpload", "CopyObject"],
    "requestParameters": {
      "bucketName": ["xxxxx-ci-cd-zip"],
      "key": ["app.zip"]
    }
  }
}
EOF
}

resource "aws_cloudwatch_event_target" "code-pipeline" {
  rule      = aws_cloudwatch_event_rule.XXXX-pipeline-event.name
  target_id = "SendToCodePipeline"
  arn       = aws_codepipeline.cicd_pipeline.arn
  role_arn  = aws_iam_role.pipeline_role.arn
}

EventBridge角色权限

data "aws_iam_policy_document" "event_bridge_role" {
  statement {
    actions = ["sts:AssumeRole"]
    effect  = "Allow"
    principals {
      type        = "Service"
      identifiers = ["events.amazonaws.com"]
    }
  }

}

resource "aws_iam_role" "pipeline_event_role" {
  name               = "xxxxx-pipeline-event-bridge-role"
  assume_role_policy = data.aws_iam_policy_document.event_bridge_role.json
}

data "aws_iam_policy_document" "pipeline_event_role_policy" {
  statement {
    sid       = ""
    actions   = ["codepipeline:StartPipelineExecution"]
    resources = ["${aws_codepipeline.cicd_pipeline.arn}"]
    effect    = "Allow"
  }
}

resource "aws_iam_policy" "pipeline_event_role_policy" {
  name   = "xxxx-codepipeline-event-role-policy"
  policy = data.aws_iam_policy_document.pipeline_event_role_policy.json
}

resource "aws_iam_role_policy_attachment" "pipeline_event_role_attach_policy" {
  role       = aws_iam_role.pipeline_event_role.name
  policy_arn = aws_iam_policy.pipeline_event_role_policy.arn
}

问题根源与修复步骤

1. 致命错误:EventBridge目标角色引用错误

你创建了专门的EventBridge角色pipeline_event_role,但在aws_cloudwatch_event_target里却引用了pipeline_role.arn,导致EventBridge没有权限调用codepipeline:StartPipelineExecution接口。

修正后的目标配置:

resource "aws_cloudwatch_event_target" "code-pipeline" {
  rule      = aws_cloudwatch_event_rule.xxxx-pipeline-event.name
  target_id = "SendToCodePipeline"
  arn       = aws_codepipeline.cicd_pipeline.arn
  role_arn  = aws_iam_role.pipeline_event_role.arn # 改为正确的角色ARN
}

2. CloudTrail事件交付验证

CloudTrail默认会把事件传给EventBridge,但你需要确保:

  • 创建CloudTrail时勾选了将事件发送到EventBridge(控制台在高级设置里;如果用Terraform,需确保event_selectors正确包含S3数据事件,且CloudTrail的区域与EventBridge规则一致)。
  • CloudTrail的数据事件选择器正确添加了目标S3桶的PutObject/CompleteMultipartUpload/CopyObject操作,未排除相关事件。

3. 简化Event Pattern测试

当前的Event Pattern严格匹配key: app.zip,如果上传的文件路径或大小写有差异会导致匹配失败。先简化规则去掉key过滤,测试是否能触发:

{
  "source": ["aws.s3"],
  "detail-type": ["AWS API Call via CloudTrail"],
  "detail": {
    "eventSource": ["s3.amazonaws.com"],
    "eventName": ["PutObject", "CompleteMultipartUpload", "CopyObject"],
    "requestParameters": {
      "bucketName": ["xxxxx-ci-cd-zip"]
    }
  }
}

4. 事件链路验证

  • 查看CloudTrail日志,确认目标S3操作事件已被记录。
  • 在EventBridge规则的监控标签下查看匹配计数,确认是否有事件命中规则。
  • 使用EventBridge的测试事件功能,模拟S3 PutObject事件,验证规则是否能触发流水线。

内容的提问来源于stack exchange,提问作者Jatin Mehrotra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 08:20:34