You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform传递SecurityGroupId至SSM自动化文档失败求助

问题描述

通过SSM Terraform模块创建Windows维护任务,编写JSON模板生成SSM自动化文档时创建成功,但调用时报错:
"The supplied parameters for invoking the specified Automation document are incorrect."

尝试用templatefile传递SecurityGroupId和AutomationAssumeRole参数,无论是否通过local变量传递均失败,不清楚如何正确将SecurityGroupId传入SSM文档。

Terraform资源代码

resource "aws_ssm_document" "t-document" {
  name          = "SGDocument"
  document_type = "Automation"
  document_format = "JSON"

  content    = templatefile("${path.module}/internet-SG.json.tpl",
    {
      SecurityGroupId      = local.SecurityGroupId 
      AutomationAssumeRole = local.AutomationAssumeRole
       
    })
}

SSM文档JSON模板

{
  "schemaVersion": "0.3",
  "parameters": {
    "SecurityGroupId": {
      "type": "String",
      "description": "(Required) The security group ID.",
      "allowedPattern": "^(sg-)([0-9a-f]){1,}$"
    },
    "AutomationAssumeRole": {
      "type": "String",
      "description": "(Optional) The ARN of the role that allows Automation to perform the actions on your behalf.",
      "default": "",
      "allowedPattern": "^arn:aws(-cn|-us-gov)?:iam::\\d{12}:role\\/[\\w+=,.@_\\/-]+|^$"
    }
  },
  "mainSteps": [
    {
      "name": "ModifySecurityGroup",
      "action": "aws:executeScript",
      "onFailure": "Abort",
      "isCritical": true,
      "isEnd": true,
      "timeoutSeconds": 600,
      "description": "## ModifySecurityGroup\nAdds a new rule to the security group allowing all traffic (0.0.0.0/0).\n## Inputs\n* SecurityGroupId: The security group ID.\n## Outputs\nThis step has no outputs.\n",
      "inputs": {
        "Runtime": "python3.7",
        "Handler": "modify_security_group_handler",
        "InputPayload": {
          "SecurityGroupId": "{{SecurityGroupId}}"
        },
        "Script": "import boto3\n\nec2_resource = boto3.resource(\"ec2\")\nec2_client = boto3.client(\"ec2\")\n\ndef modify_security_group_handler(event, context):\n    sg_id = event[\"SecurityGroupId\"]\n    sg_resource = ec2_resource.SecurityGroup(sg_id)\n    successful = True\n    errorMsg = \"\"\n    //more code"
      }
    }
  ]
}
解决方案

核心问题分析

你混淆了Terraform模板变量和SSM文档内置参数的用法:

  • 模板中的{{SecurityGroupId}}是SSM文档自身的参数引用,不是Terraform的变量语法,因此你通过templatefile传递的SecurityGroupId并未生效。
  • 当前文档定义SecurityGroupId为必填参数,调用时必须传入符合格式要求的值,否则会触发参数错误。

方案1:让SSM文档调用时动态接收参数

如果希望每次调用文档时可以指定不同的安全组ID,按以下调整:

  1. 保留SSM文档模板中的parameters定义和{{SecurityGroupId}}引用,无需通过Terraform传递该参数
  2. 修改Terraform代码,移除templatefile中的参数传递(除非需要设置默认值)
    resource "aws_ssm_document" "t-document" {
      name          = "SGDocument"
      document_type = "Automation"
      document_format = "JSON"
    
      content    = file("${path.module}/internet-SG.json.tpl")
    }
    
  3. 调用文档时,必须传入格式为sg-xxxx的SecurityGroupId参数,以及符合ARN格式的AutomationAssumeRole(如果需要)

方案2:在Terraform创建时硬编码安全组ID

如果希望文档固定操作某个安全组,无需调用时传参:

  1. 修改SSM文档模板,移除parameters中的SecurityGroupId定义
  2. 将InputPayload中的{{SecurityGroupId}}替换为Terraform模板变量${SecurityGroupId}
    {
      "schemaVersion": "0.3",
      "parameters": {
        "AutomationAssumeRole": {
          "type": "String",
          "description": "(Optional) The ARN of the role that allows Automation to perform the actions on your behalf.",
          "default": "",
          "allowedPattern": "^arn:aws(-cn|-us-gov)?:iam::\\d{12}:role\\/[\\w+=,.@_\\/-]+|^$"
        }
      },
      "mainSteps": [
        {
          "name": "ModifySecurityGroup",
          "action": "aws:executeScript",
          "onFailure": "Abort",
          "isCritical": true,
          "isEnd": true,
          "timeoutSeconds": 600,
          "description": "## ModifySecurityGroup\nAdds a new rule to the security group allowing all traffic (0.0.0.0/0).\n## Outputs\nThis step has no outputs.\n",
          "inputs": {
            "Runtime": "python3.7",
            "Handler": "modify_security_group_handler",
            "InputPayload": {
              "SecurityGroupId": "${SecurityGroupId}"
            },
            "Script": "import boto3\n\nec2_resource = boto3.resource(\"ec2\")\nec2_client = boto3.client(\"ec2\")\n\ndef modify_security_group_handler(event, context):\n    sg_id = event[\"SecurityGroupId\"]\n    sg_resource = ec2_resource.SecurityGroup(sg_id)\n    successful = True\n    errorMsg = \"\"\n    //more code"
          }
        }
      ]
    }
    
  3. 保留Terraform中templatefile的参数传递,这样创建文档时会直接把local.SecurityGroupId的值写入内容,调用时无需再传该参数

额外排查点

  • 检查调用时传入的SecurityGroupId是否严格匹配allowedPattern(必须以sg-开头,后跟16进制字符)
  • 若传入AutomationAssumeRole,确保其ARN格式符合模板中的正则规则,且该角色具备SSM自动化操作所需的权限

内容的提问来源于stack exchange,提问作者Johana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 00:12:47