Terraform错误刷新状态访问被拒绝

时间:2018-04-13 11:49:28

标签: amazon-s3 terraform bitbucket-pipelines gitbucket

我正在为我的存储库和管道使用gitbucket。 我有一个配置了远程状态的terraform配置文件,它在我的本地机器上运行正常,但在gitbucket中运行时失败。我一直得到访问拒绝错误。 这是main.tf:

terraform {
backend "s3" {
    bucket = "zego-terraform-test"
    key    = "test/terraform.tfstate"
    region = "eu-west-1"
  }
}

data "terraform_remote_state" "remote_state" {
  backend = "s3"

  config {
    bucket = "zego-terraform-test"
    key    = "test/terraform.tfstate"
    region = "eu-west-1"
  }
}

variable "region" {}

provider "aws" {
  region     = "${var.region}"
  access_key = {}
  secret_key = {}
  token      = {}
}

module "vpc" {
  source = "./modules/vpc"
}

这是我的gitbucket-pipelines.yml:

image: python:3.5.1
pipelines:
  default:
    - step:
        caches:
          - pip
        script: # Modify the commands below to build your repository.
          - apt-get update
          - apt-get install unzip
          - wget https://releases.hashicorp.com/terraform/0.11.7/terraform_0.11.7_linux_amd64.zip
          - unzip terraform_0.11.7_linux_amd64.zip
          - rm terraform_0.11.7_linux_amd64.zip
          - export PATH="$PATH:${BITBUCKET_CLONE_DIR}"
          - terraform init
            -backend-config "access_key=$AWS_ACCESS_KEY"
            -backend-config "secret_key=$AWS_SECRET_KEY"
            -backend-config "token=$TOKEN"

当我在此管道中运行.tf文件时,我收到此错误:

Successfully configured the backend "s3"! Terraform will automatically
use this backend unless the backend configuration changes.
Error refreshing state: AccessDenied: Access Denied
    status code: 403

当我删除远程状态配置时,它运行正常。 即使我在本地计算机和gitbucket环境中使用相同的信用卡,为什么我会收到拒绝访问错误?

2 个答案:

答案 0 :(得分:1)

乍一看似乎很合理。你试过将terraform init和-backend-config全部放在一行吗?我想知道 - 开头是不是搞乱了yml格式?

答案 1 :(得分:1)

得到相同的错误。对于我们的用例,我们必须手动删除terraform.tfstate目录下的.terraform/文件,然后再次运行init