You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform创建EventBridge Target报错,请求AWS/Terraform专家协助

问题:Terraform创建EventBridge Target触发SSM Document失败

尝试通过Terraform创建每20分钟触发的EventBridge Rule,关联Target调用SSM Document在已有EC2实例中运行Python脚本。手动配置该流程可正常工作,但Terraform仅Target创建步骤失败,其余资源(IAM角色、策略附加、SSM文档、EventBridge规则)均可正常创建。

原Terraform代码

provider "aws" {
    region = "us-east-1"
}

# Attach IAM Policy to the Role for Systems Manager Run Command
resource "aws_iam_role_policy_attachment" "ssm_run_command_attachment" {
    role = "Amazon_EventBridge_Invoke_Run_Command_87839596"
    policy_arn = "arn:aws:iam::123-sample:policy/service-role/Amazon_EventBridge_Invoke_Run_Command_123456"
}

# Create an SSM document
resource "aws_ssm_document" "batch_job_script_2" {
    name     = "batch-job-script-2"
    document_type = "Command"
    content    = <<EOF
{
    "schemaVersion": "2.2",
    "description": "Batch job SSM Document to run shell script",
    "parameters": {
        "commands": {
            "type": "StringList",
            "description": "(Required) The list of commands to execute.",
            "default": [
                "echo Hello World"
            ]
        }
    },
    "mainSteps": [
        {
            "action": "aws:runShellScript",
            "name": "runShellScript",
            "inputs": {
                "runCommand": [
                    "python3 ./scheduler_script.py"
                ]
            }
        }
    ]
}
EOF
}

# Create an EventBridge rule
resource "aws_cloudwatch_event_rule" "hw_eb_rule" {
    name    = "hello-world-eventbridge-rule"
    description = "Rule to trigger shell script every 20 minutes"

    schedule_expression = "rate(20 minutes)"
}

# Create a target for the EventBridge rule to run the SSM document on the EC2 instance
resource "aws_cloudwatch_event_target" "batch_job_2_target" {
    rule = aws_cloudwatch_event_rule.hw_eb_rule.name
    arn = aws_ssm_document.batch_job_script_2.arn
    role_arn = "arn:aws:iam::1234567898:role/service-role/Amazon_EventBridge_Invoke_Run_Command_123456"
    target_id = "batch-job-script-2"

    input   = jsonencode({
        "InstanceIds": ["id-12345"]
        "Parameters": {
            "commands": ["/usr/bin/python3 ./scheduler_script.py"]
        }
    })
}

错误信息

Error: creating EventBridge Target (hello-world-eventbridge-rule-batch-job-script-2): ValidationException: Parameter RunCommandParameters is not valid for target batch-job-script-2.
│ status code: 400, request id: f147023c-3bd9-4bc1-b1f2-ad8e9ab31a32
│
│ with aws_cloudwatch_event_target.batch_job_2_target,
│ on main.tf line 53, in resource "aws_cloudwatch_event_target" "batch_job_2_target":
│ 53: resource "aws_cloudwatch_event_target" "batch_job_2_target" {


解决方案

1. 修正EventBridge Target的Input结构

EventBridge触发SSM Command类型文档时,必须将实例目标参数嵌套在RunCommandParameters下,而非直接传递InstanceIds。修正后的Target代码:

# Create a target for the EventBridge rule to run the SSM document on the EC2 instance
resource "aws_cloudwatch_event_target" "batch_job_2_target" {
  rule      = aws_cloudwatch_event_rule.hw_eb_rule.name
  arn       = aws_ssm_document.batch_job_script_2.arn
  role_arn  = "arn:aws:iam::1234567898:role/service-role/Amazon_EventBridge_Invoke_Run_Command_123456"
  target_id = "batch-job-script-2"

  input = jsonencode({
    RunCommandParameters = {
      RunCommandTargets = [
        {
          Key    = "InstanceIds"
          Values = ["id-12345"]
        }
      ]
    }
  })
}

2. 简化SSM文档(可选但推荐)

原SSM文档中定义的commands参数未被实际使用(mainSteps已固定命令),移除冗余参数避免冲突:

# Create an SSM document
resource "aws_ssm_document" "batch_job_script_2" {
  name           = "batch-job-script-2"
  document_type  = "Command"
  content        = <<EOF
{
  "schemaVersion": "2.2",
  "description": "Batch job SSM Document to run shell script",
  "mainSteps": [
    {
      "action": "aws:runShellScript",
      "name": "runShellScript",
      "inputs": {
        "runCommand": [
          "python3 ./scheduler_script.py"
        ]
      }
    }
  ]
}
EOF
}

关键说明

  • EventBridge调用SSM Command文档时,必须遵循RunCommandParameters的结构要求,这是AWS服务的固定规范。
  • 确保使用的IAM角色已配置ssm:SendCommand权限,且信任策略允许events.amazonaws.com作为可信实体。

内容的提问来源于stack exchange,提问作者user23498847

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 22:45:53