使用Terraform创建EventBridge Target报错,请求AWS/Terraform专家协助
尝试通过Terraform创建每20分钟触发的EventBridge Rule,关联Target调用SSM Document在已有EC2实例中运行Python脚本。手动配置该流程可正常工作,但Terraform仅Target创建步骤失败,其余资源(IAM角色、策略附加、SSM文档、EventBridge规则)均可正常创建。
原Terraform代码
provider "aws" { region = "us-east-1" } # Attach IAM Policy to the Role for Systems Manager Run Command resource "aws_iam_role_policy_attachment" "ssm_run_command_attachment" { role = "Amazon_EventBridge_Invoke_Run_Command_87839596" policy_arn = "arn:aws:iam::123-sample:policy/service-role/Amazon_EventBridge_Invoke_Run_Command_123456" } # Create an SSM document resource "aws_ssm_document" "batch_job_script_2" { name = "batch-job-script-2" document_type = "Command" content = <<EOF { "schemaVersion": "2.2", "description": "Batch job SSM Document to run shell script", "parameters": { "commands": { "type": "StringList", "description": "(Required) The list of commands to execute.", "default": [ "echo Hello World" ] } }, "mainSteps": [ { "action": "aws:runShellScript", "name": "runShellScript", "inputs": { "runCommand": [ "python3 ./scheduler_script.py" ] } } ] } EOF } # Create an EventBridge rule resource "aws_cloudwatch_event_rule" "hw_eb_rule" { name = "hello-world-eventbridge-rule" description = "Rule to trigger shell script every 20 minutes" schedule_expression = "rate(20 minutes)" } # Create a target for the EventBridge rule to run the SSM document on the EC2 instance resource "aws_cloudwatch_event_target" "batch_job_2_target" { rule = aws_cloudwatch_event_rule.hw_eb_rule.name arn = aws_ssm_document.batch_job_script_2.arn role_arn = "arn:aws:iam::1234567898:role/service-role/Amazon_EventBridge_Invoke_Run_Command_123456" target_id = "batch-job-script-2" input = jsonencode({ "InstanceIds": ["id-12345"] "Parameters": { "commands": ["/usr/bin/python3 ./scheduler_script.py"] } }) }
错误信息
Error: creating EventBridge Target (hello-world-eventbridge-rule-batch-job-script-2): ValidationException: Parameter RunCommandParameters is not valid for target batch-job-script-2.
│ status code: 400, request id: f147023c-3bd9-4bc1-b1f2-ad8e9ab31a32
│
│ with aws_cloudwatch_event_target.batch_job_2_target,
│ on main.tf line 53, in resource "aws_cloudwatch_event_target" "batch_job_2_target":
│ 53: resource "aws_cloudwatch_event_target" "batch_job_2_target" {
解决方案
1. 修正EventBridge Target的Input结构
EventBridge触发SSM Command类型文档时,必须将实例目标参数嵌套在RunCommandParameters下,而非直接传递InstanceIds。修正后的Target代码:
# Create a target for the EventBridge rule to run the SSM document on the EC2 instance resource "aws_cloudwatch_event_target" "batch_job_2_target" { rule = aws_cloudwatch_event_rule.hw_eb_rule.name arn = aws_ssm_document.batch_job_script_2.arn role_arn = "arn:aws:iam::1234567898:role/service-role/Amazon_EventBridge_Invoke_Run_Command_123456" target_id = "batch-job-script-2" input = jsonencode({ RunCommandParameters = { RunCommandTargets = [ { Key = "InstanceIds" Values = ["id-12345"] } ] } }) }
2. 简化SSM文档(可选但推荐)
原SSM文档中定义的commands参数未被实际使用(mainSteps已固定命令),移除冗余参数避免冲突:
# Create an SSM document resource "aws_ssm_document" "batch_job_script_2" { name = "batch-job-script-2" document_type = "Command" content = <<EOF { "schemaVersion": "2.2", "description": "Batch job SSM Document to run shell script", "mainSteps": [ { "action": "aws:runShellScript", "name": "runShellScript", "inputs": { "runCommand": [ "python3 ./scheduler_script.py" ] } } ] } EOF }
关键说明
- EventBridge调用SSM Command文档时,必须遵循
RunCommandParameters的结构要求,这是AWS服务的固定规范。 - 确保使用的IAM角色已配置
ssm:SendCommand权限,且信任策略允许events.amazonaws.com作为可信实体。
内容的提问来源于stack exchange,提问作者user23498847

