You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform实现EC2实例加入AD域报错:该值无索引,求解决方案

Fixing "This value does not have any indices" Error in Terraform AD Domain Join via SSM

Let's break down what's causing your error and how to fix it step by step:

Root Cause

The error "This value does not have any indices" stems from two key issues in your code:

  1. Unreliable manual list interpolation: When you hardcode dnsIpAddresses in your SSM Document content using ${aws_directory_service_directory.ad.dns_ip_addresses[0]} and ${aws_directory_service_directory.ad.dns_ip_addresses[1]}, Terraform can't reliably resolve these list indices during the planning phase (since the AD directory resource hasn't been created yet).
  2. Mismatched SSM Document name: Your aws_ssm_association references dir_default_doc, but your actual SSM Document is named myapp_dir_default_doc—this would lead to a secondary error where the association can't locate the document.

Fixed Code

Here's the corrected version of your resources with key improvements:

1. SSM Document (Fixed List Handling)

Instead of manually writing JSON with index references, use Terraform's jsonencode function to safely serialize all values (including lists) into valid JSON:

resource "aws_ssm_document" "ad-server-domain-join-document" {
  name          = "myapp_dir_default_doc"
  document_type = "Command"
  content = jsonencode({
    schemaVersion = "1.0"
    description   = "Join an instance to a domain"
    runtimeConfig = {
      "aws:domainJoin" = {
        properties = {
          directoryId     = aws_directory_service_directory.ad.id
          directoryName   = var.dir_domain_name
          directoryOU     = var.dir_computer_ou
          dnsIpAddresses  = aws_directory_service_directory.ad.dns_ip_addresses
        }
      }
    }
  })
}
  • jsonencode automatically converts Terraform's list type (dns_ip_addresses) into a valid JSON array, eliminating the need for error-prone manual index references.
  • This also avoids syntax conflicts from mixing Terraform interpolation with raw JSON.

2. SSM Association (Fixed Document Name)

Reference the SSM Document's name directly instead of hardcoding it to ensure they always stay in sync:

resource "aws_ssm_association" "ad-server-association" {
  name         = aws_ssm_document.ad-server-domain-join-document.name
  instance_id  = aws_instance.ec2-ad-instance.id
}

Additional Checks for Smooth Domain Join

To ensure the process works end-to-end, verify these details:

  • Your EC2 instance has the SSM Agent installed (pre-installed on Amazon Linux 2, Windows Server 2016+, and most official AWS AMIs).
  • The instance's IAM role includes the AmazonSSMManagedInstanceCore policy (required for executing SSM commands) and permissions to join the AD domain.
  • Your DHCP options association (already in your code) is correctly pointing to the AD DNS servers, so the instance can resolve the domain name.
  • All variables (var.ad-password, var.dir_domain_name, var.dir_computer_ou) are set with valid, non-empty values.

内容的提问来源于stack exchange,提问作者ve05ribu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 12:13:11