使用Terraform aws_ssm_document创建SSM自动化文档时YAML验证失败
解决Terraform创建AWS SSM自动化文档的YAML格式错误问题
错误根源
你遇到的InvalidDocumentContent: YAML not well-formed错误,核心原因是Terraform配置里的content = "YAML"这一行——该值是纯字符串"YAML",并非有效的YAML结构,SSM服务解析时自然判定格式无效。
另外,当通过attachments_source指定S3源URL加载文档内容时,不需要设置content字段,若强行设置会覆盖从S3拉取的正确内容。
修正后的Terraform配置
移除无效的content字段即可,修正后的资源配置如下:
resource "aws_ssm_document" "rhel_updates" { name = "TEST-DW" document_format = "YAML" document_type = "Automation" attachments_source { key = "SourceUrl" values = ["s3://rhel/templates/101/runbooks/test.yaml"] name = "test.yaml" } }
若你的Terraform版本要求必须存在content字段,可将其设为空字符串:
resource "aws_ssm_document" "rhel_updates" { name = "TEST-DW" document_format = "YAML" content = "" document_type = "Automation" attachments_source { key = "SourceUrl" values = ["s3://rhel/templates/101/runbooks/test.yaml"] name = "test.yaml" } }
额外注意事项
- 确保Terraform执行所用的IAM角色,拥有读取目标S3对象(
s3://rhel/templates/101/runbooks/test.yaml)的权限,至少包含s3:GetObject权限。 - 确认S3中的YAML文档本身格式合规(你已手动创建成功,此步骤无需额外验证)。
内容的提问来源于stack exchange,提问作者user3362899
相关产品推荐
相关产品推荐

