You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署SSM文档报错:未知属性MonitoringRole

Fixing the "Unknown property 'MonitoringRole'" Error in AWS SSM Document Deployment

Alright, let's break down what's going wrong here and get that error sorted out.

The Root Cause

That InvalidDocumentContent: Unknown property "MonitoringRole" error is happening because you renamed a critical parameter tied directly to RDS API requirements. The original official SSM document uses MonitoringRoleArn as the parameter name—and this isn't arbitrary. When the automation runs, it calls the RDS ModifyDBInstance API, which explicitly expects a parameter named MonitoringRoleArn to enable enhanced monitoring. By changing it to MonitoringRole, you've broken that alignment, so SSM can't map your parameter to the correct API input.

Step-by-Step Fix

  1. Revert the parameter name in your remediation runbook
    Change the modified parameter definition back to the original MonitoringRoleArn (match the official document's structure):

    MonitoringRoleArn:
      type: String
      description: (Required) The ARN for the IAM role that permits RDS to send enhanced monitoring metrics to Amazon CloudWatch Logs.
      allowedPattern: ^arn:(aws[a-zA-Z-]*)?:iam::\d{12}:role/[a-zA-Z0-9+=,.@_/-]+$
    
  2. Verify parameter alignment in the triggering playbook
    Check the AFSBP_RDS.6.yaml document that calls your remediation runbook. Ensure that when it passes the IAM role ARN to ASR-EnableEnhancedMonitoringOnRDSInstance, it's using the correct MonitoringRoleArn parameter name (revert any corresponding renames here if you made them).

  3. Redeploy your Terraform resources
    Once the parameter names are back in sync with the RDS API requirements, re-run your Terraform apply. The "Unknown property" error should no longer appear, as SSM will correctly map the parameter to the underlying API call.

A Quick Note on Customizing Official Solutions

AWS's Security Hub Automated Response and Remediation solution's SSM documents are tightly integrated with AWS service APIs. Parameter names, input structures, and logic are all built to match API expectations. Tweaking parameter names without updating the corresponding API call logic in the document will almost always lead to errors like this. If you need to customize the solution, focus on modifying logic flows or adding additional steps rather than renaming core API-bound parameters.

内容的提问来源于stack exchange,提问作者Justin Lawhorne

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 17:50:22