{"id":48845,"date":"2023-03-10T11:30:52","date_gmt":"2023-08-20T06:35:16","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/"},"modified":"2024-04-29T18:13:52","modified_gmt":"2024-04-29T10:13:52","slug":"%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/","title":{"rendered":"\u4e3a\u4e86Terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd"},"content":{"rendered":"<h1>\u6982\u8ff0<\/h1>\n<p>\u5728\u8fd9\u7bc7\u6587\u7ae0\u4e2d\uff0c\u6211\u4eec\u5c06\u603b\u7ed3\u5982\u4f55\u5728Terraform\u56e2\u961f\u8fd0\u4f5c\u4e2d\u5b9e\u73b0\u6301\u7eedapply\u3002\u6211\u4eec\u7684\u57fa\u7840\u8bbe\u65bd\u73af\u5883\u662fAWS\uff0c\u4e3b\u8981\u7684\u505a\u6cd5\u4e0e\u5b9e\u8df5Terraform\u7684\u7b2c27\u7ae0&#8221;\u6301\u7eedapply\u548cTerraform\u5728\u54ea\u91cc\u6267\u884c&#8221;\uff08Continuous apply and where to execute Terraform\uff09\u4e2d\u6240\u603b\u7ed3\u7684\u51e0\u4e4e\u76f8\u540c\u3002\u5728\u5b9e\u9645\u73af\u5883\u5efa\u8bbe\u4e2d\uff0c\u6211\u4eec\u975e\u5e38\u53c2\u8003\u4e86\u8fd9\u7bc7\u6587\u7ae0\uff0c\u5e0c\u671b\u5b83\u80fd\u4f5c\u4e3a\u4e00\u4e2a\u6837\u4f8b\u5bf9\u60a8\u6709\u6240\u5e2e\u52a9\u3002<\/p>\n<h1>\u524d\u63d0 t\u00ed)<\/h1>\n<p>\u5f53\u524d\u4f7f\u7528\u7684\u662f\u5b9e\u9645\u7684\u670d\u52a1\uff0cAWS\u5e73\u53f0\u4e0a\u6709\u4e24\u4e2a\u8d26\u6237\uff0c\u5206\u522b\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u548c\u5f00\u53d1\u73af\u5883\u3002\u751f\u4ea7\u73af\u5883\u5305\u62ecproduction\u548cstaging\uff0c\u800c\u5f00\u53d1\u73af\u5883\u5219\u662fdevelopment\u3002terraform\u7684\u6e90\u4ee3\u7801\u4e0e\u5e94\u7528\u4ee3\u7801\u4e00\u8d77\u901a\u8fc7GitHub\u8fdb\u884c\u7ba1\u7406\uff0c\u91c7\u7528GitFlow\u8fdb\u884c\u8fd0\u7ef4\u3002tf\u6587\u4ef6\u5219\u901a\u8fc7terraform cloud\u8fdb\u884c\u7ba1\u7406\uff0c\u8ba1\u5212\u548c\u5e94\u7528\u5219\u57fa\u672c\u4e0a\u7531\u4e00\u4eba\u5728\u672c\u5730\u8fdb\u884c\u3002<\/p>\n<p>\u6587\u4ef6\u5939\u7684\u7ed3\u6784\u5982\u4e0b\u6240\u793a\u3002<\/p>\n<pre class=\"post-pre\"><code>app\/                        ... \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30b3\u30fc\u30c9\r\nterraform\/prod\/             ... \u672c\u756aAWS\u30a2\u30ab\u30a6\u30f3\u30c8\u7528\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\r\n              \/common       ... \u672c\u756aAWS\u30a2\u30ab\u30a6\u30f3\u30c8\u3067\u5171\u901a\u306b\u4f7f\u3046\u3082\u306e\u306etf\u30d5\u30a1\u30a4\u30eb\u7fa4\r\n              \/prod         ... production\u74b0\u5883\u3067\u4f7f\u3046\u3082\u306e\u306etf\u30d5\u30a1\u30a4\u30eb\u7fa4\r\n              \/stg          ... staging\u74b0\u5883\u3067\u4f7f\u3046\u3082\u306e\u306etf\u30d5\u30a1\u30a4\u30eb\u7fa4\r\n         \/dev\/              ... \u958b\u767aAWS\u30a2\u30ab\u30a6\u30f3\u30c8\u7528\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\r\n             \/common        ... \u958b\u767aAWS\u30a2\u30ab\u30a6\u30f3\u30c8\u3067\u5171\u901a\u306b\u4f7f\u3046\u3082\u306e\u306etf\u30d5\u30a1\u30a4\u30eb\u7fa4\r\n             \/dev           ... develop\u74b0\u5883\u3067\u4f7f\u3046\u3082\u306e\u306etf\u30d5\u30a1\u30a4\u30eb\u7fa4\r\n<\/code><\/pre>\n<h1>\u6211\u5011\u5e0c\u671b\u6b64\u6b21\u80fd\u5920\u5be6\u73fe\u7684\u76ee\u6a19\u3002<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">AWS\u4e0a\u3067plan,apply\u3092\u3055\u305b\u305f\u3044<\/ul>\n<\/li>\n<\/ul>\n<p>\u5b9f\u884c\u306b\u6642\u9593\u304c\u304b\u304b\u308b\u3082\u306e\u3092\u30ed\u30fc\u30ab\u30eb\u3067\u5b9f\u884c\u3055\u308c\u308b\u306e\u306f\u9014\u4e2d\u3067\u843d\u3061\u306a\u3044\u304b\u4e0d\u5b89<\/p>\n<p>\u8907\u6570\u4eba\u904b\u7528\u3057\u3066\u3082\u4e8b\u6545\u304c\u8d77\u3053\u3089\u306a\u3044\u3088\u3046\u306b\u3057\u305f\u3044<\/p>\n<p>\u5e38\u306b\u6700\u65b0\u306e\u72b6\u614b\u3067apply\u304c\u3055\u308c\u308b\u3088\u3046\u306b\u3057\u305f\u3044<br \/>\nterraform\u306e\u5185\u5bb9\u3092\u30ec\u30d3\u30e5\u30fc\u3057\u5408\u3048\u308b\u3088\u3046\u3057\u305f\u3044<\/p>\n<p>\u672c\u756a\u74b0\u5883\u4ee5\u5916\u306f\u3042\u308b\u7a0b\u5ea6\u67d4\u8edf\u306b\u64cd\u4f5c\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u305f\u3044<\/p>\n<p>\u958b\u767a\u74b0\u5883\u3067\u306f\u30c8\u30e9\u30a4\u30a2\u30f3\u30c9\u30a8\u30e9\u30fc\u304c\u3057\u3084\u3059\u3044\u3088\u3046\u306b\u3057\u305f\u3044\u3002<\/p>\n<p># \u6700\u540e\u6210\u529f\u5b9e\u73b0\u7684\u4e8b\u7269<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">GitHub\u3067\u30d7\u30eb\u30ea\u30af\u6642\u306bCodeBuild\u4e0a\u3067plan\u5b9f\u884c\u3001\u30de\u30fc\u30b8\u6642\u306bapply\u5b9f\u884c<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">plan,apply\u5b9f\u884c\u6642\u306b\u306fGitHub\u306e\u30b3\u30e1\u30f3\u30c8\u3068Slack\u4e21\u65b9\u306b\u901a\u77e5\u3059\u308b<\/ul>\n<\/li>\n<\/ul>\n<p>GitHub\u3060\u3051\u3060\u3068\u30de\u30fc\u30b8\u5f8c\u306bapply\u3092\u884c\u3063\u305f\u969b\u3001\u7d42\u308f\u3063\u305f\u304b\u3092\u898b\u306b\u884c\u304b\u306a\u3051\u308c\u3070\u3044\u3051\u306a\u3044\u306e\u304c\u624b\u9593\u306a\u306e\u3067<\/p>\n<p>\u672c\u756a\u3068\u672c\u756a\u5171\u901a\u306eterraform\u306fmaster\u306e\u30de\u30fc\u30b8\u6642\u306b\u305d\u308c\u4ee5\u5916\u306fdevelop\u306e\u30de\u30fc\u30b8\u6642\u306b\u884c\u3046\u3002<br \/>\n\u30ed\u30fc\u30ab\u30eb\u3067\u306fapply\u3068plan\u4e21\u65b9\u304c\u5b9f\u884c\u3067\u304d\u3066\u3057\u307e\u3046\u304c\u3001apply\u306f\u5b9f\u884c\u3057\u306a\u3044\u3068\u3044\u3046\u30eb\u30fc\u30eb\u306b\u3059\u308b<\/p>\n<p>plan\u304c\u3067\u304d\u306a\u3044\u306e\u306f\u4e0d\u4fbf\u306a\u305f\u3081\u3002apply\u304c\u3067\u304d\u308b\u306e\u306f\u585e\u304e\u305f\u304b\u3063\u305f\u304c\u3046\u307e\u304f\u3067\u304d\u305a\u4eca\u5f8c\u306e\u691c\u8a0e\u4e8b\u9805<\/p>\n<h1>\u5b9e\u65bd\u7ec6\u8282<\/h1>\n<h2>\u8bf7\u6ce8\u610f\u4ee5\u4e0b\u4e8b\u9879<\/h2>\n<p>\u8bf7\u6839\u636e\u60a8\u7684\u73af\u5883\u548c\u9700\u6c42\u6765\u4fee\u6539\u5e76\u7ecf\u8fc7\u5145\u5206\u7684\u64cd\u4f5c\u786e\u8ba4\u540e\u4f7f\u7528\u6240\u63d0\u4f9b\u7684\u4ee3\u7801\u3002\u6b64\u5916\uff0c\u7531\u4e8e\u6b64\u64cd\u4f5c\u8fd8\u6ca1\u6709\u5b8c\u5168\u6210\u719f\uff0c\u6240\u4ee5\u672a\u6765\u53ef\u80fd\u9700\u8981\u8fdb\u884c\u4fee\u6b63\u3002\u5982\u679c\u6709\u5173\u66f4\u597d\u7684\u65b9\u6cd5\u7684\u6307\u5bfc\u610f\u89c1\uff0c\u5c06\u975e\u5e38\u611f\u6fc0\uff01<\/p>\n<h2>\u6587\u4ef6\u5939\u7ed3\u6784<\/h2>\n<p>\u5728\u5236\u5b9a\u8fd9\u6b21\u65b9\u6848\u65f6\uff0c\u6211\u4eec\u6dfb\u52a0\u4e86\u4ee5\u4e0b\u5185\u5bb9\u3002<\/p>\n<pre class=\"post-pre\"><code>terraform\/continuous_apply\/script\/apply.sh        ... apply\u7528\u306e\u30b7\u30a7\u30eb\r\n                                 \/build.sh        ... apply\u304bplan\u304b\u3067\u632f\u308a\u5206\u3051\u308b\u7528\u306e\u30b7\u30a7\u30eb\r\n                                 \/install.sh      ... tfnotify\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u7528\r\n                                 \/plan.sh         ... plan\u7528\u306e\u30b7\u30a7\u30eb\r\n                          \/_terraformrc           ... terraform cloud\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u7528\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\r\n                          \/buildspec.yml          ... CodeBuild\u7528\u306eyaml\r\n                          \/tfnotify_github.yml    ... tfnotify\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3001github\u7528\r\n                          \/tfnotify_slack.yml     ... tfnotify\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3001slack\u7528\r\n<\/code><\/pre>\n<p>\u6211\u4f1a\u9010\u4e2a\u67e5\u770b\u6bcf\u4e2a\u6587\u4ef6\u3002<\/p>\n<h2>\u5728CodeBuild\u4e2d\u6267\u884c\u7684Shell\u811a\u672c<\/h2>\n<p>\u5728install.sh\u811a\u672c\u4e2d\uff0c\u6211\u4eec\u6b63\u5728\u5b89\u88c5tfnotify\u3002\u5982\u679c\u5df2\u7ecf\u6709\u4e00\u4e2a\u5305\u542btfnotify\u7684\u5bb9\u5668\u955c\u50cf\uff0c\u90a3\u5c31\u5f88\u597d\u4e86\uff0c\u6211\u4eec\u8ba1\u5212\u4ee5\u540e\u4f1a\u505a\u76f8\u5e94\u7684\u9002\u914d\u3002\u9700\u8981\u6ce8\u610f\u7684\u662f\uff0c\u7531\u4e8e\u6211\u4eec\u5b89\u88c5\u7684\u662f\u6700\u65b0\u7248\u672c\u7684tfnotify\uff0c\u6240\u4ee5\u6211\u4eec\u5df2\u7ecf\u4fee\u6539\u4e86\u5b9e\u8df5Terraform\u4e2d\u7684\u793a\u4f8b\u811a\u672c\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/sh<\/span>\r\n\r\n<span class=\"nv\">VERSION<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"v0.6.1\"<\/span>\r\n<span class=\"nv\">BASE_URL<\/span><span class=\"o\">=<\/span>https:\/\/github.com\/mercari\/tfnotify\/releases\/download\r\n<span class=\"nv\">DOWNLOAD_URL<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"nv\">BASE_URL<\/span><span class=\"k\">}<\/span><span class=\"s2\">\/<\/span><span class=\"k\">${<\/span><span class=\"nv\">VERSION<\/span><span class=\"k\">}<\/span><span class=\"s2\">\/tfnotify_linux_amd64.tar.gz\"<\/span>\r\nwget <span class=\"k\">${<\/span><span class=\"nv\">DOWNLOAD_URL<\/span><span class=\"k\">}<\/span> <span class=\"nt\">-P<\/span> \/tmp\r\n<span class=\"nb\">mkdir<\/span> <span class=\"nt\">-p<\/span> \/tmp\/tfnotify_linux_amd64\r\n<span class=\"nb\">tar <\/span>zxvf \/tmp\/tfnotify_linux_amd64.tar.gz <span class=\"nt\">-C<\/span> \/tmp\/tfnotify_linux_amd64\r\n<span class=\"nb\">mv<\/span> \/tmp\/tfnotify_linux_amd64\/tfnotify \/usr\/local\/bin\/tfnotify\r\n<\/code><\/pre>\n<p>\u5728 build.sh \u811a\u672c\u4e2d\uff0c\u6211\u4eec\u6839\u636e\u662f\u5426\u8fdb\u884c\u5408\u5e76\u548c\u5408\u5e76\u65f6\u662f\u5426\u9009\u62e9\u751f\u4ea7\u73af\u5883\u6765\u8fdb\u884c\u5206\u6d41\u3002\u7136\u800c\uff0c\u76ee\u524d\u8fd8\u65e0\u6cd5\u5c06\u8ba1\u5212\u5206\u6d41\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/sh<\/span>\r\n<span class=\"nb\">set<\/span> <span class=\"nt\">-x<\/span>\r\n\r\n<span class=\"k\">if<\/span> <span class=\"o\">[[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">CODEBUILD_WEBHOOK_TRIGGER<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'branch\/master'<\/span> <span class=\"o\">]]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then<\/span>\r\n  <span class=\"k\">${<\/span><span class=\"nv\">CODEBUILD_SRC_DIR<\/span><span class=\"k\">}<\/span>\/terraform\/continuous_apply\/scripts\/apply.sh master\r\n<span class=\"k\">elif<\/span> <span class=\"o\">[[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">CODEBUILD_WEBHOOK_TRIGGER<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'branch\/develop'<\/span> <span class=\"o\">]]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then<\/span>\r\n  <span class=\"k\">${<\/span><span class=\"nv\">CODEBUILD_SRC_DIR<\/span><span class=\"k\">}<\/span>\/terraform\/continuous_apply\/scripts\/apply.sh develop\r\n<span class=\"k\">else<\/span>\r\n  <span class=\"k\">${<\/span><span class=\"nv\">CODEBUILD_SRC_DIR<\/span><span class=\"k\">}<\/span>\/terraform\/continuous_apply\/scripts\/plan.sh\r\n<span class=\"k\">fi<\/span>\r\n<\/code><\/pre>\n<p>\u8ba1\u5212\u5c06\u83b7\u53d6\u5230\u6709\u66f4\u6539\u7684\u6587\u4ef6\u5939\uff0c\u5e76\u6267\u884cterraform apply\u3002\u4e3a\u4e86\u901a\u77e5GitHub\u548cSlack\uff0c\u6211\u5c06\u4f7f\u7528\u53cc\u91cd\u7ba1\u9053\u8fdb\u884c\u4e24\u6b21\u901a\u77e5\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/sh<\/span>\r\n\r\n<span class=\"nv\">DIRS<\/span><span class=\"o\">=<\/span><span class=\"si\">$(<\/span>git <span class=\"nt\">--no-pager<\/span> diff origin\/develop..HEAD <span class=\"nt\">--name-only<\/span> | xargs <span class=\"nt\">-I<\/span> <span class=\"o\">{}<\/span> <span class=\"nb\">dirname<\/span> <span class=\"o\">{}<\/span> | <span class=\"nb\">grep<\/span> <span class=\"s2\">\"terraform\"<\/span> | <span class=\"nb\">uniq<\/span><span class=\"si\">)<\/span>\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"nt\">-z<\/span> <span class=\"s2\">\"<\/span><span class=\"nv\">$DIRS<\/span><span class=\"s2\">\"<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n  <\/span><span class=\"nb\">echo<\/span> <span class=\"s2\">\"No directories for apply.\"<\/span>\r\n  <span class=\"nb\">exit <\/span>0\r\n<span class=\"k\">fi\r\n\r\nfor <\/span><span class=\"nb\">dir <\/span><span class=\"k\">in<\/span> <span class=\"nv\">$DIRS<\/span>\r\n<span class=\"k\">do\r\n  if<\/span> <span class=\"o\">[<\/span> <span class=\"o\">!<\/span> <span class=\"nt\">-e<\/span> <span class=\"nv\">$dir<\/span>\/terraform.tf <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    continue\r\n  fi\r\n\r\n  <\/span><span class=\"nb\">echo<\/span> <span class=\"nv\">$dir<\/span>\r\n  <span class=\"o\">(<\/span><span class=\"nb\">cd<\/span> <span class=\"nv\">$dir<\/span> <span class=\"o\">&amp;&amp;<\/span> terraform init <span class=\"nt\">-input<\/span><span class=\"o\">=<\/span><span class=\"nb\">false<\/span> <span class=\"nt\">-no-color<\/span><span class=\"o\">)<\/span>\r\n  <span class=\"o\">(<\/span><span class=\"nb\">cd<\/span> <span class=\"nv\">$dir<\/span> <span class=\"o\">&amp;&amp;<\/span> terraform plan <span class=\"nt\">-input<\/span><span class=\"o\">=<\/span><span class=\"nb\">false<\/span> <span class=\"nt\">-no-color<\/span> | tfnotify <span class=\"nt\">--config<\/span> <span class=\"k\">${<\/span><span class=\"nv\">CODEBUILD_SRC_DIR<\/span><span class=\"k\">}<\/span>\/terraform\/continuous_apply\/tfnotify_github.yml plan <span class=\"nt\">--message<\/span> <span class=\"s2\">\"<\/span><span class=\"nv\">$dir<\/span><span class=\"s2\">\"<\/span> | tfnotify <span class=\"nt\">--config<\/span> <span class=\"k\">${<\/span><span class=\"nv\">CODEBUILD_SRC_DIR<\/span><span class=\"k\">}<\/span>\/terraform\/continuous_apply\/tfnotify_slack.yml plan <span class=\"nt\">--message<\/span> <span class=\"s2\">\"<\/span><span class=\"nv\">$dir<\/span><span class=\"s2\">\"<\/span> <span class=\"o\">)<\/span>\r\n<span class=\"k\">done<\/span>\r\n<\/code><\/pre>\n<p>\u5728apply\u7684shell\u4e2d\uff0c\u57fa\u672c\u6d41\u7a0b\u4e0eplan\u76f8\u540c\uff0c\u4f46\u533a\u5206\u4e86\u662f\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u8fd8\u662f\u5176\u4ed6\u73af\u5883\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/sh<\/span>\r\n\r\n<span class=\"nv\">MODE<\/span><span class=\"o\">=<\/span><span class=\"nv\">$1<\/span>\r\n<span class=\"nv\">PROD_DIRS<\/span><span class=\"o\">=<\/span><span class=\"s1\">'terraform\/prod\/prod|terraform\/prod\/common'<\/span>\r\n\r\n<span class=\"nb\">echo<\/span> <span class=\"s2\">\"Mode: <\/span><span class=\"k\">${<\/span><span class=\"nv\">MODE<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span>\r\n\r\n<span class=\"nv\">MESSAGE<\/span><span class=\"o\">=<\/span><span class=\"si\">$(<\/span>git log <span class=\"k\">${<\/span><span class=\"nv\">CODEBUILD_SOURCE_VERSION<\/span><span class=\"k\">}<\/span> <span class=\"nt\">-1<\/span> <span class=\"nt\">--pretty<\/span><span class=\"o\">=<\/span>format:<span class=\"s2\">\"%s\"<\/span><span class=\"si\">)<\/span>\r\n<span class=\"nv\">CODEBUILD_SOURCE_VERSION<\/span><span class=\"o\">=<\/span><span class=\"si\">$(<\/span><span class=\"nb\">echo<\/span> <span class=\"k\">${<\/span><span class=\"nv\">MESSAGE<\/span><span class=\"k\">}<\/span> | <span class=\"nb\">cut<\/span> <span class=\"nt\">-f4<\/span> <span class=\"nt\">-d<\/span><span class=\"s1\">' '<\/span> | <span class=\"nb\">sed<\/span> <span class=\"s1\">'s\/#\/pr\\\/\/'<\/span><span class=\"si\">)<\/span>\r\n\r\nget_dir_list <span class=\"o\">()<\/span> <span class=\"o\">{<\/span>\r\n  <span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"nv\">$1<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'master'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    <\/span>git <span class=\"nt\">--no-pager<\/span> diff HEAD^..HEAD <span class=\"nt\">--name-only<\/span> | xargs <span class=\"nt\">-I<\/span> <span class=\"o\">{}<\/span> <span class=\"nb\">dirname<\/span> <span class=\"o\">{}<\/span> | <span class=\"nb\">grep<\/span> <span class=\"s2\">\"terraform\"<\/span> | egrep <span class=\"s2\">\"<\/span><span class=\"nv\">$2<\/span><span class=\"s2\">\"<\/span> | <span class=\"nb\">uniq\r\n  <\/span><span class=\"k\">else\r\n    <\/span>git <span class=\"nt\">--no-pager<\/span> diff HEAD^..HEAD <span class=\"nt\">--name-only<\/span> | xargs <span class=\"nt\">-I<\/span> <span class=\"o\">{}<\/span> <span class=\"nb\">dirname<\/span> <span class=\"o\">{}<\/span> | <span class=\"nb\">grep<\/span> <span class=\"s2\">\"terraform\"<\/span> | egrep <span class=\"nt\">-v<\/span> <span class=\"s2\">\"<\/span><span class=\"nv\">$2<\/span><span class=\"s2\">\"<\/span> | <span class=\"nb\">uniq\r\n  <\/span><span class=\"k\">fi<\/span>\r\n<span class=\"o\">}<\/span>\r\n\r\n<span class=\"nv\">DIRS<\/span><span class=\"o\">=<\/span><span class=\"si\">$(<\/span>get_dir_list <span class=\"nv\">$MODE<\/span> <span class=\"nv\">$PROD_DIRS<\/span><span class=\"si\">)<\/span>\r\n<span class=\"nb\">echo<\/span> <span class=\"nv\">$DIRS<\/span>\r\n\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"nt\">-z<\/span> <span class=\"s2\">\"<\/span><span class=\"nv\">$DIRS<\/span><span class=\"s2\">\"<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n  <\/span><span class=\"nb\">echo<\/span> <span class=\"s2\">\"No directories for apply.\"<\/span>\r\n  <span class=\"nb\">exit <\/span>0\r\n<span class=\"k\">fi\r\n\r\nfor <\/span><span class=\"nb\">dir <\/span><span class=\"k\">in<\/span> <span class=\"nv\">$DIRS<\/span>\r\n<span class=\"k\">do\r\n  if<\/span> <span class=\"o\">[<\/span> <span class=\"o\">!<\/span> <span class=\"nt\">-e<\/span> <span class=\"nv\">$dir<\/span>\/terraform.tf <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    continue\r\n  fi\r\n\r\n  <\/span><span class=\"nb\">echo<\/span> <span class=\"nv\">$dir<\/span>\r\n  <span class=\"o\">(<\/span><span class=\"nb\">cd<\/span> <span class=\"nv\">$dir<\/span> <span class=\"o\">&amp;&amp;<\/span> terraform init <span class=\"nt\">-input<\/span><span class=\"o\">=<\/span><span class=\"nb\">false<\/span> <span class=\"nt\">-no-color<\/span><span class=\"o\">)<\/span>\r\n  <span class=\"o\">(<\/span><span class=\"nb\">cd<\/span> <span class=\"nv\">$dir<\/span> <span class=\"o\">&amp;&amp;<\/span> terraform apply <span class=\"nt\">-input<\/span><span class=\"o\">=<\/span><span class=\"nb\">false<\/span> <span class=\"nt\">-no-color<\/span> <span class=\"nt\">-auto-approve<\/span> | tfnotify <span class=\"nt\">--config<\/span> <span class=\"k\">${<\/span><span class=\"nv\">CODEBUILD_SRC_DIR<\/span><span class=\"k\">}<\/span>\/terraform\/continuous_apply\/tfnotify_github.yml apply <span class=\"nt\">--message<\/span> <span class=\"s2\">\"<\/span><span class=\"nv\">$dir<\/span><span class=\"s2\">\"<\/span> | tfnotify <span class=\"nt\">--config<\/span> <span class=\"k\">${<\/span><span class=\"nv\">CODEBUILD_SRC_DIR<\/span><span class=\"k\">}<\/span>\/terraform\/continuous_apply\/tfnotify_slack.yml apply <span class=\"nt\">--message<\/span> <span class=\"s2\">\"<\/span><span class=\"nv\">$dir<\/span><span class=\"s2\">\"<\/span> <span class=\"o\">)<\/span>\r\n<span class=\"k\">done<\/span>\r\n<\/code><\/pre>\n<h2>\u6784\u5efa\u89c4\u8303\u6587\u4ef6 buildspec.yml \u548c tfnotify \u7684\u914d\u7f6e<\/h2>\n<p>\u4ee5\u4e0b\u662f\u7528\u4e8e\u5728CodeBuild\u4e2d\u5b9e\u73b0\u7684\u6784\u5efa\u89c4\u8303\uff08builspec\uff09\u3002<br \/>\n\u91cd\u70b9\u662f\u5728\u5b89\u88c5\u65f6\u5b89\u88c5\u4e86tfnotify\uff0c\u5e76\u6dfb\u52a0\u4e86\u5b58\u653eTerraform Cloud\u914d\u7f6e\u6587\u4ef6\u7684\u5904\u7406\u8fc7\u7a0b\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">version<\/span><span class=\"pi\">:<\/span> <span class=\"m\">0.2<\/span>\r\n\r\n<span class=\"na\">env<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">parameter-store<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">GITHUB_TOKEN<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">\/continuous_apply\/github_token\"<\/span>\r\n    <span class=\"na\">TERRAFROM_CLOUD_TOKEN<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">\/continuous_apply\/terraform_cloud_token\"<\/span>\r\n    <span class=\"na\">SLACK_TOKEN<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">\/continuous_apply\/slack_token\"<\/span>\r\n\r\n<span class=\"na\">phases<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">install<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">commands<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">${CODEBUILD_SRC_DIR}\/terraform\/continuous_apply\/scripts\/install.sh<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">sed -e \"s\/_TOKEN_\/${TERRAFROM_CLOUD_TOKEN}\/\" ${CODEBUILD_SRC_DIR}\/terraform\/continuous_apply\/_terraformrc &gt; ~\/.terraformrc<\/span>\r\n\r\n  <span class=\"na\">build<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">commands<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">${CODEBUILD_SRC_DIR}\/terraform\/continuous_apply\/scripts\/build.sh<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>credentials \"app.terraform.io\" {\r\n  token = \"_TOKEN_\"\r\n}\r\n<\/code><\/pre>\n<p>\u4ee5\u4e0b\u662ftfnotify\u7684\u8a2d\u5b9a\u3002\u70ba\u4e86\u6613\u8b80\u6027\uff0c\u6211\u5011\u5728GitHub\u548cSlack\u4e0a\u66f4\u6539\u4e86\u683c\u5f0f\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">ci<\/span><span class=\"pi\">:<\/span> <span class=\"s\">codebuild<\/span>\r\n<span class=\"na\">notifier<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">github<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">token<\/span><span class=\"pi\">:<\/span> <span class=\"s\">$GITHUB_TOKEN<\/span>\r\n    <span class=\"na\">repository<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">owner<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">(__secret__)\"<\/span>\r\n      <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">(__secret__)\"<\/span>\r\n<span class=\"na\">terraform<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">plan<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">template<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">|<\/span>\r\n      <span class=\"s\">{{ .Title }}<\/span>\r\n      <span class=\"s\">{{ .Message }}<\/span>\r\n      <span class=\"s\">{{if .Result}}&lt;pre&gt;&lt;code&gt; {{ .Result }} &lt;\/pre&gt;&lt;\/code&gt;{{end}}<\/span>\r\n      <span class=\"s\">&lt;details&gt;&lt;summary&gt;Details (Click me)&lt;\/summary&gt;<\/span>\r\n      <span class=\"s\">&lt;pre&gt;&lt;code&gt; {{ .Body }} &lt;\/pre&gt;&lt;\/code&gt;&lt;\/details&gt;<\/span>\r\n  <span class=\"na\">apply<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">template<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">|<\/span>\r\n      <span class=\"s\">{{ .Title }}<\/span>\r\n      <span class=\"s\">{{ .Message }}<\/span>\r\n      <span class=\"s\">{{if .Result}}&lt;pre&gt;&lt;code&gt; {{ .Result }} &lt;\/pre&gt;&lt;\/code&gt;{{end}}<\/span>\r\n      <span class=\"s\">&lt;details&gt;&lt;summary&gt;Details (Click me)&lt;\/summary&gt;<\/span>\r\n      <span class=\"s\">&lt;pre&gt;&lt;code&gt; {{ .Body }} &lt;\/pre&gt;&lt;\/code&gt;&lt;\/details&gt;<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"na\">ci<\/span><span class=\"pi\">:<\/span> <span class=\"s\">codebuild<\/span>\r\n<span class=\"na\">notifier<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">slack<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">token<\/span><span class=\"pi\">:<\/span> <span class=\"s\">$SLACK_TOKEN<\/span>\r\n    <span class=\"na\">channel<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">(__secret__)\"<\/span>\r\n    <span class=\"na\">bot<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">(__secret__)\"<\/span>\r\n<span class=\"na\">terraform<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">plan<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">template<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">|<\/span>\r\n      <span class=\"s\">{{ .Title }}<\/span>\r\n      <span class=\"s\">{{ .Message }}<\/span>\r\n      <span class=\"s\">{{if .Result}}<\/span>\r\n      <span class=\"s\">```<\/span>\r\n      <span class=\"s\">{{ .Result }}<\/span>\r\n      <span class=\"s\">```<\/span>\r\n      <span class=\"s\">{{end}}<\/span>\r\n      <span class=\"s\">```<\/span>\r\n      <span class=\"s\">{{ .Body }}<\/span>\r\n      <span class=\"s\">```<\/span>\r\n  <span class=\"na\">apply<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">template<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">|<\/span>\r\n      <span class=\"s\">{{ .Title }}<\/span>\r\n      <span class=\"s\">{{ .Message }}<\/span>\r\n      <span class=\"s\">{{if .Result}}<\/span>\r\n      <span class=\"s\">```<\/span>\r\n      <span class=\"s\">{{ .Result }}<\/span>\r\n      <span class=\"s\">```<\/span>\r\n      <span class=\"s\">{{end}}<\/span>\r\n      <span class=\"s\">```<\/span>\r\n      <span class=\"s\">{{ .Body }}<\/span>\r\n      <span class=\"s\">```<\/span>\r\n<\/code><\/pre>\n<h2>AWS\u7684\u914d\u7f6e<\/h2>\n<p>\u6211\u6b63\u5728\u4f7f\u7528Terraform\u8fdb\u884c\u7f16\u5199\u3002\u5b9e\u9645\u4e0a\uff0c\u6211\u4eec\u9700\u8981\u4e00\u4e2a\u7528\u4e8e\u751f\u4ea7\u548c\u4e00\u4e2a\u7528\u4e8e\u5f00\u53d1\u7684\u73af\u5883\uff0c\u4ee5\u4e0b\u662f\u7528\u4e8e\u5f00\u53d1\u73af\u5883\u7684\u90e8\u5206\u3002<br \/>\n\u4e3a\u4e86\u907f\u514d\u4e0d\u5fc5\u8981\u7684\u6784\u5efa\uff0c\u5728\u8fd9\u91cc\u4e5f\u901a\u8fc7\u4fee\u6539\u6587\u4ef6\u5939\u8fdb\u884c\u8fc7\u6ee4\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nx\">resource<\/span> <span class=\"s2\">\"aws_codebuild_project\"<\/span> <span class=\"s2\">\"continuous_apply\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">name<\/span>         <span class=\"p\">=<\/span> <span class=\"s2\">\"${var.project}-common-continuous-apply\"<\/span>\r\n  <span class=\"nx\">service_role<\/span> <span class=\"p\">=<\/span> <span class=\"nx\">module<\/span><span class=\"err\">.<\/span><span class=\"nx\">continuous_apply_codebuild_role<\/span><span class=\"err\">.<\/span><span class=\"nx\">iam_role_arn<\/span>\r\n\r\n  <span class=\"nx\">source<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">type<\/span>      <span class=\"p\">=<\/span> <span class=\"s2\">\"GITHUB\"<\/span>\r\n    <span class=\"nx\">location<\/span>  <span class=\"p\">=<\/span> <span class=\"s2\">\"(_secret_)\"<\/span>\r\n    <span class=\"nx\">buildspec<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"terraform\/continuous_apply\/buildspec.yml\"<\/span>\r\n  <span class=\"p\">}<\/span>\r\n\r\n  <span class=\"nx\">artifacts<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">type<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"NO_ARTIFACTS\"<\/span>\r\n  <span class=\"p\">}<\/span>\r\n\r\n  <span class=\"nx\">environment<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">type<\/span>            <span class=\"p\">=<\/span> <span class=\"s2\">\"LINUX_CONTAINER\"<\/span>\r\n    <span class=\"nx\">compute_type<\/span>    <span class=\"p\">=<\/span> <span class=\"s2\">\"BUILD_GENERAL1_SMALL\"<\/span>\r\n    <span class=\"nx\">image<\/span>           <span class=\"p\">=<\/span> <span class=\"s2\">\"hashicorp\/terraform:0.12.25\"<\/span>\r\n    <span class=\"nx\">privileged_mode<\/span> <span class=\"p\">=<\/span> <span class=\"kc\">false<\/span>\r\n  <span class=\"p\">}<\/span>\r\n\r\n  <span class=\"nx\">provisioner<\/span> <span class=\"s2\">\"local-exec\"<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">command<\/span> <span class=\"p\">=<\/span> <span class=\"o\">&lt;&lt;-<\/span><span class=\"no\">EOT<\/span><span class=\"sh\">\r\n      aws codebuild import-source-credentials \\\r\n        --server-type GITHUB \\\r\n        --auth-type PERSONAL_ACCESS_TOKEN \\\r\n        --token $GITHUB_TOKEN\r\n<\/span><span class=\"no\">    EOT\r\n\r\n<\/span>    <span class=\"nx\">environment<\/span> <span class=\"p\">=<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"nx\">GITHUB_TOKEN<\/span> <span class=\"p\">=<\/span> <span class=\"nx\">data<\/span><span class=\"err\">.<\/span><span class=\"nx\">aws_ssm_parameter<\/span><span class=\"err\">.<\/span><span class=\"nx\">github_token<\/span><span class=\"err\">.<\/span><span class=\"nx\">value<\/span>\r\n    <span class=\"p\">}<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"nx\">resource<\/span> <span class=\"s2\">\"aws_codebuild_webhook\"<\/span> <span class=\"s2\">\"continuous_apply\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">project_name<\/span> <span class=\"p\">=<\/span> <span class=\"nx\">aws_codebuild_project<\/span><span class=\"err\">.<\/span><span class=\"nx\">continuous_apply<\/span><span class=\"err\">.<\/span><span class=\"nx\">name<\/span>\r\n\r\n  <span class=\"nx\">filter_group<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">filter<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"nx\">type<\/span>    <span class=\"p\">=<\/span> <span class=\"s2\">\"EVENT\"<\/span>\r\n      <span class=\"nx\">pattern<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"PULL_REQUEST_CREATED\"<\/span>\r\n    <span class=\"p\">}<\/span>\r\n\r\n    <span class=\"nx\">filter<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"nx\">exclude_matched_pattern<\/span> <span class=\"p\">=<\/span> <span class=\"kc\">false<\/span>\r\n      <span class=\"nx\">pattern<\/span>                 <span class=\"p\">=<\/span> <span class=\"s2\">\"^terraform\/dev\/\"<\/span>\r\n      <span class=\"nx\">type<\/span>                    <span class=\"p\">=<\/span> <span class=\"s2\">\"FILE_PATH\"<\/span>\r\n    <span class=\"p\">}<\/span>\r\n  <span class=\"p\">}<\/span>\r\n\r\n  <span class=\"nx\">filter_group<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">filter<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"nx\">type<\/span>    <span class=\"p\">=<\/span> <span class=\"s2\">\"EVENT\"<\/span>\r\n      <span class=\"nx\">pattern<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"PULL_REQUEST_UPDATED\"<\/span>\r\n    <span class=\"p\">}<\/span>\r\n\r\n    <span class=\"nx\">filter<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"nx\">exclude_matched_pattern<\/span> <span class=\"p\">=<\/span> <span class=\"kc\">false<\/span>\r\n      <span class=\"nx\">pattern<\/span>                 <span class=\"p\">=<\/span> <span class=\"s2\">\"^terraform\/dev\/\"<\/span>\r\n      <span class=\"nx\">type<\/span>                    <span class=\"p\">=<\/span> <span class=\"s2\">\"FILE_PATH\"<\/span>\r\n    <span class=\"p\">}<\/span>\r\n  <span class=\"p\">}<\/span>\r\n\r\n  <span class=\"nx\">filter_group<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">filter<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"nx\">type<\/span>    <span class=\"p\">=<\/span> <span class=\"s2\">\"EVENT\"<\/span>\r\n      <span class=\"nx\">pattern<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"PULL_REQUEST_REOPENED\"<\/span>\r\n    <span class=\"p\">}<\/span>\r\n\r\n    <span class=\"nx\">filter<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"nx\">exclude_matched_pattern<\/span> <span class=\"p\">=<\/span> <span class=\"kc\">false<\/span>\r\n      <span class=\"nx\">pattern<\/span>                 <span class=\"p\">=<\/span> <span class=\"s2\">\"^terraform\/dev\/\"<\/span>\r\n      <span class=\"nx\">type<\/span>                    <span class=\"p\">=<\/span> <span class=\"s2\">\"FILE_PATH\"<\/span>\r\n    <span class=\"p\">}<\/span>\r\n  <span class=\"p\">}<\/span>\r\n\r\n  <span class=\"nx\">filter_group<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">filter<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"nx\">type<\/span>    <span class=\"p\">=<\/span> <span class=\"s2\">\"EVENT\"<\/span>\r\n      <span class=\"nx\">pattern<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"PUSH\"<\/span>\r\n    <span class=\"p\">}<\/span>\r\n\r\n    <span class=\"nx\">filter<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"nx\">type<\/span>    <span class=\"p\">=<\/span> <span class=\"s2\">\"HEAD_REF\"<\/span>\r\n      <span class=\"nx\">pattern<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"develop\"<\/span>\r\n    <span class=\"p\">}<\/span>\r\n\r\n    <span class=\"nx\">filter<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"nx\">exclude_matched_pattern<\/span> <span class=\"p\">=<\/span> <span class=\"kc\">false<\/span>\r\n      <span class=\"nx\">pattern<\/span>                 <span class=\"p\">=<\/span> <span class=\"s2\">\"^terraform\/dev\/\"<\/span>\r\n      <span class=\"nx\">type<\/span>                    <span class=\"p\">=<\/span> <span class=\"s2\">\"FILE_PATH\"<\/span>\r\n    <span class=\"p\">}<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<h2>GitHub\u7684\u914d\u7f6e\u8bbe\u7f6e<\/h2>\n<p>\u4e0d\u4f1a\u63d0\u4f9b\u8be6\u7ec6\u8bf4\u660e\uff0c\u4f46\u662f\u4e3a\u4e86\u4e8b\u6545\u9632\u6b62\uff0c\u6211\u4eec\u5728\u5206\u652f\u4e2d\u8fdb\u884c\u4e86\u4ee5\u4e0b\u8bbe\u7f6e\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Require pull request reviews before merging<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Require branches to be up to date before merging<\/ul>\n<h1>\u603b\u7ed3<\/h1>\n<p>\u7ecf\u8fc7\u4ee5\u4e0a\u7684\u5de5\u4f5c\uff0c\u6211\u4eec\u5df2\u7ecf\u6210\u529f\u5730\u5efa\u7acb\u8d77\u4e86\u4e00\u4e2a\u6301\u7eed\u7533\u8bf7\u7684\u673a\u5236\u3002\u867d\u7136\u4e0d\u80fd\u5b8c\u5168\u79f0\u4e4b\u4e3a\u7262\u56fa\u7684\u8fd0\u4f5c\u548c\u6846\u67b6\uff0c\u4f46\u4e0e\u4e4b\u524d\u53ea\u80fd\u7531\u4e00\u4e2a\u4eba\u6765\u5904\u7406\u7684\u60c5\u51b5\u76f8\u6bd4\uff0c\u73b0\u5728\u8fd0\u7528\u8d77\u6765\u53d8\u5f97\u66f4\u52a0\u4fbf\u5229\u3002\u5e0c\u671b\u60a8\u80fd\u53c2\u8003\u5e76\u5e2e\u52a9\u6211\u4eec\u6784\u5efa\u8fd9\u4e2a\u673a\u5236\u3002<\/p>\n<h1>\u8bf7\u53c2\u8003<\/h1>\n<p>\u6211\u4e4b\u524d\u5df2\u7ecf\u63d0\u5230\u8fc7\uff0c\u4f46\u662f\u518d\u6b21\u603b\u7ed3\u4e00\u4e0b\u3002\u8fd9\u4e9b\u5185\u5bb9\u975e\u5e38\u6709\u53c2\u8003\u4ef7\u503c\u3002\u8c22\u8c22\uff01<\/p>\n<p>\u5b9f\u8df5Terraform \u7b2c27\u7ae0 \u7d99\u7d9a\u7684apply<br \/>\nTerraform \u3069\u3053\u3067\u5b9f\u884c\u3057\u3066\u3044\u307e\u3059\u304b\uff1f<br \/>\n\u30e1\u30eb\u30ab\u30ea Microservices Team \u306b\u3088\u308b Terraform \u904b\u7528\u3068\u305d\u306e\u4e2d\u3067\u958b\u767a\u3057\u305fOSS\u306e\u7d39\u4ecb<br \/>\ngithub.com\/mercari\/tfnotify<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8ff0 \u5728\u8fd9\u7bc7\u6587\u7ae0\u4e2d\uff0c\u6211\u4eec\u5c06\u603b\u7ed3\u5982\u4f55\u5728Terraform\u56e2\u961f\u8fd0\u4f5c\u4e2d\u5b9e\u73b0\u6301\u7eedapply\u3002\u6211\u4eec\u7684\u57fa\u7840\u8bbe\u65bd\u73af\u5883\u662fAWS [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-48845","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u4e3a\u4e86Terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4e3a\u4e86terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u4e3a\u4e86Terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd\" \/>\n<meta property=\"og:description\" content=\"\u6982\u8ff0 \u5728\u8fd9\u7bc7\u6587\u7ae0\u4e2d\uff0c\u6211\u4eec\u5c06\u603b\u7ed3\u5982\u4f55\u5728Terraform\u56e2\u961f\u8fd0\u4f5c\u4e2d\u5b9e\u73b0\u6301\u7eedapply\u3002\u6211\u4eec\u7684\u57fa\u7840\u8bbe\u65bd\u73af\u5883\u662fAWS [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4e3a\u4e86terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-20T06:35:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-29T10:13:52+00:00\" \/>\n<meta name=\"author\" content=\"\u6e05, \u5b87\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u6e05, \u5b87\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/\",\"name\":\"\u4e3a\u4e86Terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-08-20T06:35:16+00:00\",\"dateModified\":\"2024-04-29T10:13:52+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/1a6ecd3d914d22a5ac32791ffc1fbd8e\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u4e3a\u4e86Terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/1a6ecd3d914d22a5ac32791ffc1fbd8e\",\"name\":\"\u6e05, \u5b87\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4b2016c18459a605fc469c7566608f5686491baa112d0871ee613f61b7210565?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4b2016c18459a605fc469c7566608f5686491baa112d0871ee613f61b7210565?s=96&d=mm&r=g\",\"caption\":\"\u6e05, \u5b87\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/qingyu\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u4e3a\u4e86Terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u4e3a\u4e86terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u4e3a\u4e86Terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd","og_description":"\u6982\u8ff0 \u5728\u8fd9\u7bc7\u6587\u7ae0\u4e2d\uff0c\u6211\u4eec\u5c06\u603b\u7ed3\u5982\u4f55\u5728Terraform\u56e2\u961f\u8fd0\u4f5c\u4e2d\u5b9e\u73b0\u6301\u7eedapply\u3002\u6211\u4eec\u7684\u57fa\u7840\u8bbe\u65bd\u73af\u5883\u662fAWS [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u4e3a\u4e86terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-08-20T06:35:16+00:00","article_modified_time":"2024-04-29T10:13:52+00:00","author":"\u6e05, \u5b87","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u6e05, \u5b87","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"4 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/","name":"\u4e3a\u4e86Terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-08-20T06:35:16+00:00","dateModified":"2024-04-29T10:13:52+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/1a6ecd3d914d22a5ac32791ffc1fbd8e"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u4e3a\u4e86Terraform\u56e2\u961f\u7684\u8fd0\u8425\uff0c\u6211\u4eec\u6240\u91c7\u53d6\u7684\u63aa\u65bd"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/1a6ecd3d914d22a5ac32791ffc1fbd8e","name":"\u6e05, \u5b87","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4b2016c18459a605fc469c7566608f5686491baa112d0871ee613f61b7210565?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4b2016c18459a605fc469c7566608f5686491baa112d0871ee613f61b7210565?s=96&d=mm&r=g","caption":"\u6e05, \u5b87"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/qingyu\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%b8%ba%e4%ba%86terraform%e5%9b%a2%e9%98%9f%e7%9a%84%e8%bf%90%e8%90%a5%ef%bc%8c%e6%88%91%e4%bb%ac%e6%89%80%e9%87%87%e5%8f%96%e7%9a%84%e6%8e%aa%e6%96%bd%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/48845","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=48845"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/48845\/revisions"}],"predecessor-version":[{"id":86842,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/48845\/revisions\/86842"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=48845"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=48845"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=48845"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}