You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决Drone中ECS部署调用ECR最新镜像的问题?

解决方案

一、Drone步骤间共享变量的实现方法

Drone的每个步骤默认是独立容器,环境变量不互通,可通过挂载工作区写入文件的方式共享变量:

  1. 在aws-cli步骤中,将获取到的镜像信息写入工作区文件:
# 获取最新镜像标签(提交哈希)并写入文件
aws ecr describe-images --repository-name your-ruby-repo --query 'sort_by(imageDetails,& imagePushedAt)[-1].imageTags[0]' --output text > ./latest_image_tag.txt
  1. 在fabfuel/ecs-deploy步骤中,读取工作区文件中的变量:
steps:
  - name: fetch-image-tag
    image: amazon/aws-cli
    environment:
      AWS_ACCESS_KEY_ID:
        from_secret: aws_access_key
      AWS_SECRET_ACCESS_KEY:
        from_secret: aws_secret_key
    commands:
      - aws ecr describe-images --repository-name your-ruby-repo --query 'sort_by(imageDetails,& imagePushedAt)[-1].imageTags[0]' --output text > ./latest_image_tag.txt

  - name: deploy-to-ecs
    image: fabfuel/ecs-deploy
    environment:
      AWS_ACCESS_KEY_ID:
        from_secret: aws_access_key
      AWS_SECRET_ACCESS_KEY:
        from_secret: aws_secret_key
    commands:
      - IMAGE_NAME=your-ecr-uri:$(cat ./latest_image_tag.txt)
      - ecs-deploy -c your-ecs-cluster -n your-service-name -i $IMAGE_NAME

注:Drone默认会为所有步骤挂载同一工作区,无需额外配置;若自定义了工作区路径,需确保两个步骤的workspace配置一致。

二、给fabfuel/ecs-deploy添加aws-cli的替代方案

如果不想用文件共享,可自定义封装包含aws-cli的ecs-deploy镜像:

  1. 创建Dockerfile:
FROM fabfuel/ecs-deploy:latest
RUN apk add --no-cache aws-cli
  1. 构建并推送到你的ECR仓库:
docker build -t your-ecr-uri/ecs-deploy-with-awscli:latest .
docker push your-ecr-uri/ecs-deploy-with-awscli:latest
  1. 在Drone流水线中使用自定义镜像,直接执行ECR命令:
steps:
  - name: deploy-to-ecs
    image: your-ecr-uri/ecs-deploy-with-awscli:latest
    environment:
      AWS_ACCESS_KEY_ID:
        from_secret: aws_access_key
      AWS_SECRET_ACCESS_KEY:
        from_secret: aws_secret_key
    commands:
      - IMAGE_TAG=$(aws ecr describe-images --repository-name your-ruby-repo --query 'sort_by(imageDetails,& imagePushedAt)[-1].imageTags[0]' --output text)
      - ecs-deploy -c your-ecs-cluster -n your-service-name -i your-ecr-uri:$IMAGE_TAG

三、跨仓库传递镜像提交哈希的最优方案

要将镜像的提交哈希从镜像推送仓库传递到部署仓库,可通过Drone的Repository Dispatch功能触发部署流水线并携带参数:

  1. 在镜像推送仓库的Drone配置中,添加触发部署的步骤:
steps:
  - name: push-ruby-image
    # 你的镜像构建、推送步骤...

  - name: trigger-deploy-pipeline
    image: plugins/github
    settings:
      token:
        from_secret: github_token
      repository: your-org/deployment-repo
      event_type: deploy-ruby-image
      client_payload:
        full_image_name: your-ecr-uri:${DRONE_COMMIT_SHA}
  1. 在部署仓库的.drone.yml中,监听该事件并使用传递的参数:
kind: pipeline
type: docker
name: ruby-service-deploy

trigger:
  event:
    - repository_dispatch
  repository_dispatch:
    type:
      - deploy-ruby-image

steps:
  - name: deploy-to-ecs
    image: fabfuel/ecs-deploy
    environment:
      AWS_ACCESS_KEY_ID:
        from_secret: aws_access_key
      AWS_SECRET_ACCESS_KEY:
        from_secret: aws_secret_key
    commands:
      - ecs-deploy -c your-ecs-cluster -n your-service-name -i ${DRONE_REPOSITORY_DISPATCH_PAYLOAD_FULL_IMAGE_NAME}

这种方式无需查询ECR,直接将镜像推送仓库的提交哈希作为标签传递,同时实现了流水线的自动化触发。


内容的提问来源于stack exchange,提问作者Grant Callant

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 10:20:42