You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用jq动态构建GitHub Actions策略矩阵及CloudFormation参数JSON

GitHub Actions 纯jq实现terraform.tfvars转多格式AWS参数方案

实现逻辑

全程用jq原生能力完成解析和格式转换,无额外bash字符串处理,在build-matrix作业一次性生成所有需要的JSON格式,作为作业输出直接供下游调用,避免重复解析:

  • 先用base64解码Secrets中存储的tfvars内容
  • jq以原始文本模式逐行读取内容,自动跳过空行、#开头的注释行,通过正则匹配键 = "值"格式(兼容键值间任意数量空格),解析为标准键值对JSON对象
  • 基于同一个解析后的对象,一次性派生3种目标格式:GitHub Actions策略矩阵、CloudFormation Stack参数、CloudFormation StackSets参数

完整工作流代码

name: Test
on:
  workflow_dispatch:

jobs:
  build-matrix:
    name: Build JSON from PARAMS
    runs-on: ubuntu-latest
    outputs:
      matrix: ${{ steps.gen-json.outputs.matrix }}
      cfn_stack_params: ${{ steps.gen-json.outputs.cfn_stack_params }}
      cfn_stacksets_params: ${{ steps.gen-json.outputs.cfn_stacksets_params }}
    steps:
      - name: Generate all required JSON formats
        id: gen-json
        run: |
          # 解码base64存储的tfvars内容
          echo '${{ secrets.PARAMS }}' | base64 -d > terraform.tfvars
          
          # 纯jq解析+多格式生成
          jq -c -Rsn '
            # 解析tfvars为标准键值对对象
            $_parsed := [
              inputs | split("\n")[]
              | select(length > 0)
              | select(ltrimstr(" ") | startswith("#") | not)
              | capture("^\\s*(?<key>[a-zA-Z0-9_-]+)\\s*=\\s*\"(?<value>.*)\"\\s*$")
              | {(.key): .value}
            ] | add // {}

            # 输出三种格式到对应结构
            | {
                matrix: {include: [.]},
                cfn_stack_params: [to_entries[] | {ParameterKey: .key, ParameterValue: .value}],
                cfn_stacksets_params: [to_entries[] | {Key: .key, Value: .value}]
              }
          ' terraform.tfvars > gen_result.json

          # 写入GitHub Actions输出
          echo "matrix=$(jq -c '.matrix' gen_result.json)" >> $GITHUB_OUTPUT
          echo "cfn_stack_params=$(jq -c '.cfn_stack_params' gen_result.json)" >> $GITHUB_OUTPUT
          echo "cfn_stacksets_params=$(jq -c '.cfn_stacksets_params' gen_result.json)" >> $GITHUB_OUTPUT

  check-matrix:
    name: Check Parameters
    runs-on: ubuntu-latest
    needs: build-matrix
    strategy:
      matrix: ${{fromJson(needs.build-matrix.outputs.matrix)}}
    steps:
      - name: Verify parameters
        run: |
          # 直接取矩阵变量
          echo "unique_prefix: ${{ matrix.unique_prefix }}"
          echo "base_region: ${{ matrix.base_region }}"

          # 验证CloudFormation参数格式
          echo "CFN Stack params:"
          echo '${{ needs.build-matrix.outputs.cfn_stack_params }}' | jq .
          echo "CFN StackSets params:"
          echo '${{ needs.build-matrix.outputs.cfn_stacksets_params }}' | jq .

下游调用方法

  • 矩阵变量使用:和原有逻辑完全一致,在配置了strategy.matrix的作业中,直接通过${{ matrix.键名 }}获取单个变量值,比如${{ matrix.base_region }}可直接用于角色assume等非CloudFormation场景
  • CloudFormation Stack部署:将输出的cfn_stack_params写入文件,直接传给--parameter-overrides参数:
    echo '${{ needs.build-matrix.outputs.cfn_stack_params }}' > stack-params.json
    aws cloudformation deploy \
      --stack-name your-stack \
      --template-file template.yaml \
      --parameter-overrides file://stack-params.json
    
  • CloudFormation StackSets部署:将输出的cfn_stacksets_params写入文件,直接传给--parameters参数:
    echo '${{ needs.build-matrix.outputs.cfn_stacksets_params }}' > stackset-params.json
    aws cloudformation create-stack-instances \
      --stack-set-name your-stackset \
      --regions ${{ matrix.base_region }} \
      --parameters file://stackset-params.json
    

注意事项

  • 存储在Secrets中的PARAMS需为无换行折行的base64编码内容,本地生成命令为base64 -w 0 terraform.tfvars,可完整保留原始tfvars的换行和格式
  • 解析逻辑默认支持字符串类型的tfvars变量,自动跳过空行和#开头的注释行,键名支持字母、数字、下划线、中划线
  • 所有转换逻辑无sed/awk等字符串处理依赖,不会出现特殊字符转义异常

内容的提问来源于stack exchange,提问作者Papina

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.29 05:55:05