Azure YAML流水线中Terraform漂移检测无法识别-detailed-exitcode求助
问题分析与修复
你的脚本核心问题在于仅在terraform plan返回非0退出码时才赋值exit_status,当命令返回0(无变更)时,exit_status会保留之前命令的残留值,导致后续判断逻辑失效。另外,你期望漂移时终止流水线,但当前分支里返回2时仅打印信息未退出,需要补充终止逻辑。
修复后的脚本
- bash: | terraform init -reconfigure terraform validate # 直接捕获所有退出码,无论命令返回0/1/2 terraform plan -detailed-exitcode -out=FILE_NEW exit_status=$? if [ $exit_status -eq 0 ]; then echo "No changes, not applying" elif [ $exit_status -eq 1 ]; then echo "Terraform plan failed" exit 1 elif [ $exit_status -eq 2 ]; then echo "Drift Detected, terminating pipeline" exit 1 # 添加该命令终止流水线 fi displayName: Detecting Terraform Drift
替代方案(不依赖-detailed-exitcode)
方案1:解析terraform plan文本输出
通过匹配输出中的关键字段判断是否存在变更:
terraform plan -out=FILE_NEW | tee plan_output.txt # 检查输出中是否包含变更统计(如"Plan: 2 to change") if grep -q "Plan: [1-9]" plan_output.txt; then echo "Drift Detected, terminating pipeline" exit 1 elif grep -q "No changes." plan_output.txt; then echo "No changes, not applying" else echo "Terraform plan failed" exit 1 fi
方案2:JSON输出+jq解析
利用-json参数生成结构化输出,通过jq工具统计变更资源数:
terraform plan -json -out=FILE_NEW > plan.json # 计算待变更的资源总数 change_count=$(jq '.resource_changes | length' plan.json) if [ "$change_count" -gt 0 ]; then echo "Drift Detected ($change_count resources to modify), terminating pipeline" exit 1 else echo "No changes, not applying" fi
方案3:解析Terraform Plan文件
通过terraform show解析生成的plan文件,判断变更情况:
terraform plan -out=FILE_NEW terraform show -json FILE_NEW | jq '.resource_changes | length' > change_count.txt if [ "$(cat change_count.txt)" -gt 0 ]; then echo "Drift Detected, terminating pipeline" exit 1 else echo "No changes, not applying" fi
内容的提问来源于stack exchange,提问作者Buhu
相关产品推荐
相关产品推荐

