如何将GitHub Webhook参数、Helm镜像信息传入Tekton Pipeline?
Tekton 参数提取与传递实现方案
一、GitHub Webhook 参数传入 Tekton Pipeline
需要通过Tekton Triggers组件完成Webhook参数的接收和映射,操作步骤如下:
- 在
TriggerTemplate中定义与GitHub Webhook payload字段对应的Pipeline参数,映射后传递给PipelineRun
# trigger-template.yaml 示例 apiVersion: triggers.tekton.dev/v1beta1 kind: TriggerTemplate spec: params: - name: git-repo-url description: GitHub 仓库地址,来自Webhook payload的repository.url字段 - name: git-revision description: 提交哈希,来自Webhook payload的after字段 resourcetemplates: - apiVersion: tekton.dev/v1beta1 kind: PipelineRun spec: pipelineRef: name: your-pipeline params: - name: REPO_URL value: $(tt.params.git-repo-url) - name: REVISION value: $(tt.params.git-revision)
- 在
TriggerBinding中完成Webhook payload字段到TriggerTemplate参数的映射
# trigger-binding.yaml 示例 apiVersion: triggers.tekton.dev/v1beta1 kind: TriggerBinding spec: params: - name: git-repo-url value: $(body.repository.url) - name: git-revision value: $(body.after)
EventListener收到GitHub Webhook请求后,会自动提取payload对应字段,通过TriggerTemplate传递给PipelineRun,在Pipeline中定义同名接收参数即可拿到对应值。
二、从Helm清单提取字段传递给Tekton Task
需要先将代码拉取到Pipeline共享工作区,再通过yq工具读取Helm配置字段,推荐两种实现方案可按需选择:
方案1:新增前置Task提取参数(推荐,参数可跨Task复用)
新增专门的Helm字段提取Task,将读取结果输出为Task结果,再传递给已有Task
- 第一步:定义提取字段的Task
# helm-extract-task.yaml apiVersion: tekton.dev/v1beta1 kind: Task metadata: name: extract-helm-params spec: workspaces: - name: source description: 存放拉取后源码的工作区 results: - name: image-repo description: 从values.yaml读取的镜像仓库地址 - name: image-tag description: 从Chart.yaml读取的镜像标签 steps: - name: extract-fields image: mikefarah/yq:4 script: | # 读取values.yaml的image字段写入结果 yq eval '.image' $(workspaces.source.path)/values.yaml | tr -d '\n' > $(results.image-repo.path) # 读取Chart.yaml的appVersion字段写入结果 yq eval '.appVersion' $(workspaces.source.path)/Chart.yaml | tr -d '\n' > $(results.image-tag.path)
- 第二步:在Pipeline中编排执行顺序,传递提取结果给已有Task
注:你原有Task的
IMAGE_TAG参数描述写错了,建议修正为The image tag
# pipeline.yaml 示例 apiVersion: tekton.dev/v1beta1 kind: Pipeline spec: workspaces: - name: shared-workspace tasks: - name: fetch-source taskRef: name: git-clone workspaces: - name: output workspace: shared-workspace params: - name: url value: $(params.REPO_URL) - name: revision value: $(params.REVISION) - name: extract-helm taskRef: name: extract-helm-params runAfter: ["fetch-source"] workspaces: - name: source workspace: shared-workspace - name: your-existing-task taskRef: name: your-task-name # 替换为你已定义的Task名称 runAfter: ["extract-helm"] params: - name: IMAGE_REPO value: $(tasks.extract-helm.results.image-repo) - name: IMAGE_TAG value: $(tasks.extract-helm.results.image-tag)
方案2:直接在现有Task内部提取参数
如果参数仅在单个Task内部使用,无需跨Task传递,可以直接在现有Task的steps最前面增加提取步骤,读取值作为环境变量供后续步骤使用:
# 改造后的tekton-task.yaml示例 apiVersion: tekton.dev/v1beta1 kind: Task metadata: name: your-task-name spec: workspaces: - name: source description: 存放源码的工作区 params: - name: IMAGE_REPO description: The image registry - name: IMAGE_TAG description: The image tag steps: - name: extract-helm-fields image: mikefarah/yq:4 script: | export IMAGE_REPO=$(yq eval '.image' $(workspaces.source.path)/values.yaml) export IMAGE_TAG=$(yq eval '.appVersion' $(workspaces.source.path)/Chart.yaml) # 后续步骤直接调用上述两个环境变量即可 # 原有后续步骤不变
内容的提问来源于stack exchange,提问作者Ash Poblete
相关产品推荐
相关产品推荐

