You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Gitlab CI/CD中应用aws-auth ConfigMap到EKS集群出现YAML解析错误

问题根因

  • 你生成的authconfig.yaml中包含了Terraform输出时自带的<<EOT/EOT heredoc边界标记,这些标记不属于合法的K8s YAML内容,是触发解析报错的直接原因
  • 当前输出的mapRoles下的username、groups字段缩进错误,比上级的rolearn多了2个空格,也会导致YAML结构解析异常
  • 本地执行无报错的原因大概率是你本地手动移除了边界标记/修正了缩进,或者本地Terraform版本和CI环境运行的版本不同,部分较新版本Terraform输出raw字符串时会自动剥离heredoc标记

解决步骤

  1. 生成authconfig.yaml时添加-raw参数,直接输出字符串内容,避免包含heredoc边界符:
terraform output -raw authconfig > authconfig.yaml
  1. 修正Terraform中authconfig输出的mapRoles缩进,确保username、groups和rolearn处于同级缩进:
output "authconfig" {
  value = <<EOT
apiVersion: v1
kind: ConfigMap
metadata:
    name: aws-auth
    namespace: kube-system
data:
    mapRoles: |
      - rolearn: "arn:aws:iam::503655390180:role/clusters-production-workers"
        username: system:node:{{EC2PrivateDNSName}}
        groups:
            - system:bootstrappers
            - system:nodes
EOT
}
  1. 可在CI流程中增加YAML合法性校验步骤,提前拦截格式问题:
# 用yamllint检查结构
yamllint authconfig.yaml
# 或用kubectl dry run验证配置有效性
kubectl create -f authconfig.yaml -n kube-system --dry-run=client

内容的提问来源于stack exchange,提问作者Milton Jesus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.30 07:15:05