使用Terraform传递SecurityGroupId至SSM自动化文档失败求助
问题描述
通过SSM Terraform模块创建Windows维护任务,编写JSON模板生成SSM自动化文档时创建成功,但调用时报错:
"The supplied parameters for invoking the specified Automation document are incorrect."
尝试用templatefile传递SecurityGroupId和AutomationAssumeRole参数,无论是否通过local变量传递均失败,不清楚如何正确将SecurityGroupId传入SSM文档。
Terraform资源代码
resource "aws_ssm_document" "t-document" { name = "SGDocument" document_type = "Automation" document_format = "JSON" content = templatefile("${path.module}/internet-SG.json.tpl", { SecurityGroupId = local.SecurityGroupId AutomationAssumeRole = local.AutomationAssumeRole }) }
SSM文档JSON模板
{ "schemaVersion": "0.3", "parameters": { "SecurityGroupId": { "type": "String", "description": "(Required) The security group ID.", "allowedPattern": "^(sg-)([0-9a-f]){1,}$" }, "AutomationAssumeRole": { "type": "String", "description": "(Optional) The ARN of the role that allows Automation to perform the actions on your behalf.", "default": "", "allowedPattern": "^arn:aws(-cn|-us-gov)?:iam::\\d{12}:role\\/[\\w+=,.@_\\/-]+|^$" } }, "mainSteps": [ { "name": "ModifySecurityGroup", "action": "aws:executeScript", "onFailure": "Abort", "isCritical": true, "isEnd": true, "timeoutSeconds": 600, "description": "## ModifySecurityGroup\nAdds a new rule to the security group allowing all traffic (0.0.0.0/0).\n## Inputs\n* SecurityGroupId: The security group ID.\n## Outputs\nThis step has no outputs.\n", "inputs": { "Runtime": "python3.7", "Handler": "modify_security_group_handler", "InputPayload": { "SecurityGroupId": "{{SecurityGroupId}}" }, "Script": "import boto3\n\nec2_resource = boto3.resource(\"ec2\")\nec2_client = boto3.client(\"ec2\")\n\ndef modify_security_group_handler(event, context):\n sg_id = event[\"SecurityGroupId\"]\n sg_resource = ec2_resource.SecurityGroup(sg_id)\n successful = True\n errorMsg = \"\"\n //more code" } } ] }
解决方案
核心问题分析
你混淆了Terraform模板变量和SSM文档内置参数的用法:
- 模板中的
{{SecurityGroupId}}是SSM文档自身的参数引用,不是Terraform的变量语法,因此你通过templatefile传递的SecurityGroupId并未生效。 - 当前文档定义
SecurityGroupId为必填参数,调用时必须传入符合格式要求的值,否则会触发参数错误。
方案1:让SSM文档调用时动态接收参数
如果希望每次调用文档时可以指定不同的安全组ID,按以下调整:
- 保留SSM文档模板中的
parameters定义和{{SecurityGroupId}}引用,无需通过Terraform传递该参数 - 修改Terraform代码,移除
templatefile中的参数传递(除非需要设置默认值)resource "aws_ssm_document" "t-document" { name = "SGDocument" document_type = "Automation" document_format = "JSON" content = file("${path.module}/internet-SG.json.tpl") } - 调用文档时,必须传入格式为
sg-xxxx的SecurityGroupId参数,以及符合ARN格式的AutomationAssumeRole(如果需要)
方案2:在Terraform创建时硬编码安全组ID
如果希望文档固定操作某个安全组,无需调用时传参:
- 修改SSM文档模板,移除
parameters中的SecurityGroupId定义 - 将
InputPayload中的{{SecurityGroupId}}替换为Terraform模板变量${SecurityGroupId}{ "schemaVersion": "0.3", "parameters": { "AutomationAssumeRole": { "type": "String", "description": "(Optional) The ARN of the role that allows Automation to perform the actions on your behalf.", "default": "", "allowedPattern": "^arn:aws(-cn|-us-gov)?:iam::\\d{12}:role\\/[\\w+=,.@_\\/-]+|^$" } }, "mainSteps": [ { "name": "ModifySecurityGroup", "action": "aws:executeScript", "onFailure": "Abort", "isCritical": true, "isEnd": true, "timeoutSeconds": 600, "description": "## ModifySecurityGroup\nAdds a new rule to the security group allowing all traffic (0.0.0.0/0).\n## Outputs\nThis step has no outputs.\n", "inputs": { "Runtime": "python3.7", "Handler": "modify_security_group_handler", "InputPayload": { "SecurityGroupId": "${SecurityGroupId}" }, "Script": "import boto3\n\nec2_resource = boto3.resource(\"ec2\")\nec2_client = boto3.client(\"ec2\")\n\ndef modify_security_group_handler(event, context):\n sg_id = event[\"SecurityGroupId\"]\n sg_resource = ec2_resource.SecurityGroup(sg_id)\n successful = True\n errorMsg = \"\"\n //more code" } } ] } - 保留Terraform中
templatefile的参数传递,这样创建文档时会直接把local.SecurityGroupId的值写入内容,调用时无需再传该参数
额外排查点
- 检查调用时传入的
SecurityGroupId是否严格匹配allowedPattern(必须以sg-开头,后跟16进制字符) - 若传入
AutomationAssumeRole,确保其ARN格式符合模板中的正则规则,且该角色具备SSM自动化操作所需的权限
内容的提问来源于stack exchange,提问作者Johana
相关产品推荐
相关产品推荐

