如何通过GitHub Workflows批量部署多套Terraform环境并避免步骤重复
问题描述
我的Terraform项目结构如下:
environments |- dev |- staging modules
每个环境的状态都存储在S3中,且基于modules目录创建资源。请问如何通过GitHub工作流一次性部署所有Terraform环境,无需为每个环境目录重复编写init、plan、apply步骤?
以下是我当前用于部署dev环境的yml文件:
name: Terraform Deployment after push on: push: branches: - main permissions: id-token: write contents: write env: AWS_REGION: us-east-1 jobs: merged: name: deploy runs-on: ubuntu-20.04 steps: - name: Check out code uses: actions/checkout@v2 - name: Setup Terraform uses: hashicorp/setup-terraform@v1 with: terraform_version: 1.2.6 - name: Run terraform fmt check id: fmt run: terraform fmt -check -diff -recursive - name: Configure AWS Credentials uses: aws-actions/configure-aws-credentials@v1 with: aws-region: ${{ env.AWS_REGION }} role-to-assume: ${{ secrets.ROLE }} role-session-name: InfraDeployOnMerge - name: Initialize Terraform id: init run: | cd environments/dev rm -rf .terraform.* terraform init -input=false - name: Terraform Validate id: validate run: terraform validate -no-color - name: Terraform Plan id: plan run: | cd environments/dev terraform plan -var="aws_region=${{ env.AWS_REGION }}" -var="aws_profile=" -input=false -no-color -out=tfplan \ && terraform show -no-color tfplan continue-on-error: true - name: Apply Terraform if: steps.plan.outcome == 'success' id: apply continue-on-error: true run: | cd environments/dev terraform apply -input=false -no-color \ tfplan
解决方案
你可以通过GitHub Actions的**矩阵策略(Matrix Strategy)**实现一次性部署所有环境,核心是将环境列表定义为矩阵变量,让工作流自动循环处理每个环境,无需重复编写步骤。
修改后的完整工作流文件如下:
name: Terraform Deployment after push on: push: branches: - main permissions: id-token: write contents: write env: AWS_REGION: us-east-1 jobs: deploy: name: Deploy ${{ matrix.environment }} environment runs-on: ubuntu-20.04 strategy: matrix: environment: [dev, staging] # 列出所有需要部署的环境 steps: - name: Check out code uses: actions/checkout@v2 - name: Setup Terraform uses: hashicorp/setup-terraform@v1 with: terraform_version: 1.2.6 - name: Run terraform fmt check id: fmt run: terraform fmt -check -diff -recursive - name: Configure AWS Credentials uses: aws-actions/configure-aws-credentials@v1 with: aws-region: ${{ env.AWS_REGION }} role-to-assume: ${{ secrets.ROLE }} role-session-name: InfraDeployOnMerge-${{ matrix.environment }} # 为每个环境设置独立会话名称 - name: Initialize Terraform id: init run: | cd environments/${{ matrix.environment }} rm -rf .terraform.* terraform init -input=false - name: Terraform Validate id: validate run: | cd environments/${{ matrix.environment }} terraform validate -no-color - name: Terraform Plan id: plan run: | cd environments/${{ matrix.environment }} terraform plan -var="aws_region=${{ env.AWS_REGION }}" -var="aws_profile=" -input=false -no-color -out=tfplan \ && terraform show -no-color tfplan continue-on-error: true - name: Apply Terraform if: steps.plan.outcome == 'success' id: apply continue-on-error: true run: | cd environments/${{ matrix.environment }} terraform apply -input=false -no-color tfplan
关键修改说明:
- 矩阵策略配置:在
jobs.deploy.strategy.matrix中定义环境列表[dev, staging],工作流会自动为每个环境创建独立运行实例。 - 动态环境路径:所有涉及环境目录的命令(如
cd)替换为environments/${{ matrix.environment }},自动适配当前循环的环境。 - 独立会话名称:AWS角色会话名称添加
-${{ matrix.environment }}后缀,便于区分不同环境的部署会话。 - 任务名称动态化:任务名称改为
Deploy ${{ matrix.environment }} environment,在GitHub Actions控制台中可清晰看到每个环境的部署任务。
修改后,每次推送代码到main分支时,工作流会同时(或按顺序,取决于并发设置)处理dev和staging两个环境的部署,完全复用同一套步骤逻辑。
内容的提问来源于stack exchange,提问作者Valip
相关产品推荐
相关产品推荐

