如何将CloudFormation中PowerShell脚本输出发送至指定邮箱?
实现CloudFormation模板中PowerShell脚本输出的邮件发送
我正在编写一个CloudFormation模板,其中会运行两个PowerShell脚本,需要获取这两个脚本的输出,并发送到CloudFormation参数指定的邮箱。以下是我的现有代码:
AWSTemplateFormatVersion: '2010-09-09' Description: Test Document Resources: SSMUpgradeDocument: Type: AWS::SSM::Document Properties: DocumentType: Command Name: "Test Upgrade" Content: schemaVersion: '2.2' description: "Test Upgrade" parameters: Emails: type: String description: |- enter the email address to send the overall output mainSteps: - action: "aws:runPowerShellScript" name: "DriverUpgrade" precondition: StringEquals: ["platformType", "Windows"] inputs: runCommand: [] timeoutSeconds: 3600 onFailure: Continue maxAttempts: 1 isCritical: False nextStep: Second Driver - action: "aws:runPowerShellScript" name: "SecondDriverUpgrade" precondition: StringEquals: ["platformType", "Windows"] inputs: runCommand: [] timeoutSeconds: 3600 onFailure: Continue isCritical: False
解决方案代码
AWSTemplateFormatVersion: '2010-09-09' Description: Test Document Resources: SSMUpgradeDocument: Type: AWS::SSM::Document Properties: DocumentType: Command Name: "Test Upgrade" Content: schemaVersion: '2.2' description: "Test Upgrade" parameters: Emails: type: String description: |- enter the email address to send the overall output mainSteps: - action: "aws:runPowerShellScript" name: "DriverUpgrade" precondition: StringEquals: ["platformType", "Windows"] inputs: runCommand: - "# 你的第一个PowerShell脚本逻辑" - "Write-Output 'DriverUpgrade脚本执行结果:完成X驱动更新'" timeoutSeconds: 3600 onFailure: Continue maxAttempts: 1 isCritical: False nextStep: SecondDriverUpgrade outputs: - Name: DriverUpgradeOutput Selector: "$.stdout" Type: String - action: "aws:runPowerShellScript" name: "SecondDriverUpgrade" precondition: StringEquals: ["platformType", "Windows"] inputs: runCommand: - "# 你的第二个PowerShell脚本逻辑" - "Write-Output 'SecondDriverUpgrade脚本执行结果:完成Y驱动更新'" timeoutSeconds: 3600 onFailure: Continue isCritical: False outputs: - Name: SecondDriverUpgradeOutput Selector: "$.stdout" Type: String - action: "aws:executeAwsApi" name: "SendUpgradeResultsEmail" inputs: Service: ses Api: SendEmail Destination: ToAddresses: - "{{ Emails }}" Message: Body: Text: Charset: UTF-8 Data: | 驱动升级脚本执行结果汇总: --- 第一个脚本输出:{{ DriverUpgrade.DriverUpgradeOutput }} 第二个脚本输出:{{ SecondDriverUpgrade.SecondDriverUpgradeOutput }} Subject: Charset: UTF-8 Data: "驱动升级任务执行结果通知" Source: "verified-sender@example.com" # 替换为AWS SES已验证的发件邮箱
关键修改说明
- 补全资源名称:原模板Resources块缺少具体资源标识,补充为
SSMUpgradeDocument以符合CloudFormation语法规范。 - 捕获脚本输出:在每个PowerShell步骤中添加
outputs字段,通过Selector: "$.stdout"捕获脚本的标准输出,生成可被后续步骤调用的变量。 - 新增邮件发送步骤:使用
aws:executeAwsApi调用AWS SES的SendEmail接口,将两个脚本的输出拼接为邮件内容,发送到参数指定的目标邮箱。
注意事项
- 发件邮箱必须在AWS SES中完成验证(或所在域名已验证),否则无法发送邮件。
- 执行SSM命令的EC2实例需要具备调用SES
SendEmail的IAM权限,需在实例关联的IAM角色中添加如下策略:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "ses:SendEmail", "Resource": "*" } ] }
- 若需处理脚本执行失败的场景,可在邮件内容中加入步骤状态信息,例如
{{ DriverUpgrade.Status }}。
内容的提问来源于stack exchange,提问作者shubham kamboj
相关产品推荐
相关产品推荐

