我有CodeBuild项目和Lambda函数。我希望每次CodeBuild构建成功时都执行lambda函数。由于某种原因,根本没有调用Lambda。这是我的lambda和事件规则/目标的terraform配置:
resource "aws_iam_role" "iam_for_lambda" {
name = "invalidate_cache_${var.name}"
assume_role_policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "sts:AssumeRole",
"Principal": {
"Service": "lambda.amazonaws.com"
},
"Effect": "Allow",
"Sid": ""
}
]
}
EOF
}
resource "aws_iam_role_policy" "invalidate_cache" {
name = "invalidate_cache_${var.name}-policy"
role="${aws_iam_role.iam_for_lambda.id}"
policy= <<PATTERN
{
"Id": "InvalidateCachePolicy",
"Version": "2012-10-17",
"Statement": [
{
"Action": [
"cloudfront:CreateInvalidation",
"cloudfront:GetInvalidation",
"cloudfront:ListInvalidations"
],
"Effect": "Allow",
"Resource": "*"
}
]
}
PATTERN
}
resource "aws_lambda_function" "invalidate_cache" {
filename = local.lambda_path
function_name = "invalidate_cache_${var.name}"
role = "${aws_iam_role.iam_for_lambda.arn}"
handler = "index.handler"
source_code_hash = "${filebase64sha256(local.lambda_path)}"
runtime = "nodejs10.x"
environment {
variables = {
CLOUDFRONT_DISTRIBUTION_ID = "${aws_cloudfront_distribution.website_distribution.id}"
}
}
depends_on = [null_resource.deps]
}
locals {
lambda_path = split("|", join("|", ["./../lambda/invalidateCache/invalidateCache.zip", null_resource.deps.id]))[0]
}
resource "aws_cloudwatch_event_rule" "invalidate_cache" {
count = var.codebuild_project_name == "" ? 0 : 1
name = "invalidate-cache-${var.name}"
event_pattern = <<PATTERN
{
"source": [
"aws.codebuild"
],
"detail-type": [
"CodeBuild Build Success"
],
"detail": {
"build-status": [
"SUCCEEDED"
],
"project-name": [${jsonencode(var.codebuild_project_name)}]
}
}
PATTERN
}
resource "aws_cloudwatch_event_target" "invalidate_cache" {
count = var.codebuild_project_name == "" ? 0 : 1
rule = "${aws_cloudwatch_event_rule.invalidate_cache[0].name}"
target_id = "invalidate-cache-${var.name}"
arn = "${aws_lambda_function.invalidate_cache.arn}"
}
resource "aws_lambda_permission" "invalidate_cache" {
count = var.codebuild_project_name == "" ? 0 : 1
statement_id = "AllowExecutionFromCloudWatch"
action = "lambda:InvokeFunction"
function_name = "${aws_lambda_function.invalidate_cache.function_name}"
principal = "events.amazonaws.com"
source_arn = "${aws_cloudwatch_event_rule.invalidate_cache[0].arn}"
}
由于某些原因,当“前端”项目的构建成功时,不会调用lambda。在lambda页面上的AWS控制台中,我看到lambda触发器设置正确,并且在cloudwatch事件中看起来还可以(但在指标中没有任何lambda执行)。还手动测试了lambda,它可以工作。因此,看来我的事件规则不正确,事件从未触发,但无法找出问题所在。
以下模式对我有用(似乎详细类型阻止了正确的事件处理):
{
"source": [
"aws.codebuild"
],
"detail": {
"build-status": [
"SUCCEEDED"
],
"project-name": ["frontend"]
}
}
答案 0 :(得分:2)
您的cloudwatch事件规则与明细类型不匹配。至少根据示例事件
resource "aws_cloudwatch_event_rule" "invalidate_cache" {
count = var.codebuild_project_name == "" ? 0 : 1
name = "invalidate-cache-${var.name}"
event_pattern = <<PATTERN
{
"source": [
"aws.codebuild"
],
"detail-type": [
"CodeBuild Build State Change"
],
"detail": {
"build-status": [
"SUCCEEDED"
],
"project-name": [${jsonencode(var.codebuild_project_name)}]
}
}
PATTERN
}
这是AWS为成功的代码构建状态更改提供的示例事件。当您手动创建事件规则时,它来自AWS控制台。
{
"version": "0",
"id": "bfdc1220-60ff-44ad-bfa7-3b6e6ba3b2d0",
"detail-type": "CodeBuild Build State Change",
"source": "aws.codebuild",
"account": "123456789012",
"time": "2017-07-12T00:42:28Z",
"region": "us-east-1",
"resources": [
"arn:aws:codebuild:us-east-1:123456789012:build/SampleProjectName:ed6aa685-0d76-41da-a7f5-6d8760f41f55"
],
"detail": {
"build-status": "SUCCEEDED",
"project-name": "SampleProjectName",
"build-id": "arn:aws:codebuild:us-east-1:123456789012:build/SampleProjectName:ed6aa685-0d76-41da-a7f5-6d8760f41f55",
"current-phase": "COMPLETED",
"current-phase-context": "[]",
"version": "1"
}
}
如果由于某种原因更新的模式不起作用,我要做的一件事是将服务中的所有事件发送到只打印事件的lambda,以便我可以看到当前结构。在这种情况下,您的事件规则将如下所示:
{
"source": [
"aws.codebuild"
]
}