You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用CDK构建多Pipeline检测Stack及集成Linting工具?

实现方案

一、Pipeline失败告警CDK Stack实现

核心思路

通过EventBridge捕获Pipeline执行失败事件,或用CloudWatch Alarm监控失败指标,将告警推送至SNS主题,再通过邮件、Slack等渠道通知相关人员。

代码实现(TypeScript)

方式1:EventBridge捕获失败事件

直接匹配所有Pipeline的FAILED状态事件,触发SNS告警:

import * as cdk from 'aws-cdk-lib';
import * as events from 'aws-cdk-lib/aws-events';
import * as targets from 'aws-cdk-lib/aws-events-targets';
import * as sns from 'aws-cdk-lib/aws-sns';
import * as subscriptions from 'aws-cdk-lib/aws-sns-subscriptions';

export class PipelineMonitoringStack extends cdk.Stack {
  constructor(scope: cdk.App, id: string, props?: cdk.StackProps) {
    super(scope, id, props);

    // 创建SNS告警主题
    const pipelineAlarmTopic = new sns.Topic(this, 'PipelineFailureAlarmTopic');
    // 添加邮件订阅
    pipelineAlarmTopic.addSubscription(new subscriptions.EmailSubscription('alert-recipient@example.com'));

    // 配置EventBridge规则,捕获所有Pipeline失败事件
    const pipelineFailureRule = new events.Rule(this, 'PipelineFailureRule', {
      eventPattern: {
        source: ['aws.codepipeline'],
        detailType: ['CodePipeline Pipeline Execution State Change'],
        detail: {
          state: ['FAILED']
        }
      }
    });

    // 将SNS主题设为规则目标
    pipelineFailureRule.addTarget(new targets.SnsTopic(pipelineAlarmTopic));
  }
}

方式2:CloudWatch Alarm监控失败指标

通过监控FailedPipelineExecutions指标实现告警,适合关注趋势类场景:

import * as cdk from 'aws-cdk-lib';
import * as cloudwatch from 'aws-cdk-lib/aws-cloudwatch';
import * as actions from 'aws-cdk-lib/aws-cloudwatch-actions';
import * as sns from 'aws-cdk-lib/aws-sns';
import * as subscriptions from 'aws-cdk-lib/aws-sns-subscriptions';

export class PipelineMonitoringStack extends cdk.Stack {
  constructor(scope: cdk.App, id: string, props?: cdk.StackProps) {
    super(scope, id, props);

    const pipelineAlarmTopic = new sns.Topic(this, 'PipelineFailureAlarmTopic');
    pipelineAlarmTopic.addSubscription(new subscriptions.EmailSubscription('alert-recipient@example.com'));

    // 创建CloudWatch告警
    const pipelineFailureAlarm = new cloudwatch.Alarm(this, 'PipelineFailureAlarm', {
      metric: new cloudwatch.Metric({
        namespace: 'AWS/CodePipeline',
        metricName: 'FailedPipelineExecutions',
        dimensionsMap: { PipelineName: '*' }, // 监控所有Pipeline,可指定具体名称
        statistic: 'Sum',
        period: cdk.Duration.minutes(5),
      }),
      threshold: 1,
      evaluationPeriods: 1,
      alarmDescription: '当有Pipeline执行失败时触发告警',
    });

    // 绑定SNS告警动作
    pipelineFailureAlarm.addAlarmAction(new actions.SnsAction(pipelineAlarmTopic));
  }
}

二、为所有Pipeline集成Linting工具

核心思路

针对新建Pipeline,直接在Build阶段插入Linting步骤;针对现有Pipeline,用CDK的Aspect机制批量注入Linting动作。Linting通过CodeBuild执行,根据技术栈选择对应工具。

1. 新建Pipeline时直接集成

以TypeScript项目为例,添加ESLint检查步骤:

import * as cdk from 'aws-cdk-lib';
import * as codepipeline from 'aws-cdk-lib/aws-codepipeline';
import * as codepipeline_actions from 'aws-cdk-lib/aws-codepipeline-actions';
import * as codebuild from 'aws-cdk-lib/aws-codebuild';

export class PipelineWithLintStack extends cdk.Stack {
  constructor(scope: cdk.App, id: string, props?: cdk.StackProps) {
    super(scope, id, props);

    // 定义Pipeline源输出
    const sourceOutput = new codepipeline.Artifact();
    const sourceAction = new codepipeline_actions.CodeCommitSourceAction({
      actionName: 'Source',
      repository: codecommit.Repository.fromRepositoryName(this, 'Repo', 'your-repo-name'),
      output: sourceOutput,
    });

    // 创建Linting用CodeBuild项目
    const lintProject = new codebuild.PipelineProject(this, 'LintProject', {
      buildSpec: codebuild.BuildSpec.fromObject({
        version: '0.2',
        phases: {
          install: { commands: ['npm install'] },
          build: { commands: ['npm run lint'] }, // 对应package.json中的lint脚本
        },
      }),
      environment: {
        buildImage: codebuild.LinuxBuildImage.STANDARD_7_0, // 适配Node.js环境
      },
    });

    // 构建Pipeline
    const pipeline = new codepipeline.Pipeline(this, 'AppPipeline', {
      stages: [
        { stageName: 'Source', actions: [sourceAction] },
        {
          stageName: 'Lint',
          actions: [
            new codepipeline_actions.CodeBuildAction({
              actionName: 'RunLint',
              project: lintProject,
              input: sourceOutput,
            }),
          ],
        },
        // 后续添加编译、测试、部署阶段
      ],
    });
  }
}

2. 用Aspect批量修改现有Pipeline

自动为Stack中所有Pipeline插入Linting阶段:

import { IAspect, Aspects } from 'aws-cdk-lib';
import { CfnPipeline } from 'aws-cdk-lib/aws-codepipeline';

// 定义Aspect类
class AddLintingAspect implements IAspect {
  visit(node: cdk.IConstruct): void {
    if (node instanceof CfnPipeline) {
      const stages = node.stages || [];
      // 在Source阶段后插入Linting阶段
      stages.splice(1, 0, {
        name: 'Linting',
        actions: [
          {
            name: 'RunLint',
            actionTypeId: {
              category: 'Build',
              owner: 'AWS',
              provider: 'CodeBuild',
              version: '1',
            },
            configuration: {
              ProjectName: 'your-shared-lint-project', // 提前创建的通用Linting CodeBuild项目
            },
            inputArtifacts: [{ name: 'SourceArtifact' }], // 对应源输出名称
            runOrder: 1,
          },
        ],
      });
      node.stages = stages;
    }
  }
}

// 在Stack中应用Aspect
Aspects.of(this).add(new AddLintingAspect());

注意事项

  • 根据技术栈调整Linting命令:Python用pylint,Java用Checkstyle,Terraform用terraform validate等。
  • Linting步骤设为runOrder: 1,确保在编译、测试前执行,失败则终止流水线。
  • 确保CodeBuild项目有权限访问Pipeline的源代码(如CodeCommit、S3等)。

内容的提问来源于stack exchange,提问作者Carolina Freitas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 04:30:30