Terraform部署SSM文档报错:未知属性MonitoringRole
Alright, let's break down what's going wrong here and get that error sorted out.
The Root Cause
That InvalidDocumentContent: Unknown property "MonitoringRole" error is happening because you renamed a critical parameter tied directly to RDS API requirements. The original official SSM document uses MonitoringRoleArn as the parameter name—and this isn't arbitrary. When the automation runs, it calls the RDS ModifyDBInstance API, which explicitly expects a parameter named MonitoringRoleArn to enable enhanced monitoring. By changing it to MonitoringRole, you've broken that alignment, so SSM can't map your parameter to the correct API input.
Step-by-Step Fix
Revert the parameter name in your remediation runbook
Change the modified parameter definition back to the originalMonitoringRoleArn(match the official document's structure):MonitoringRoleArn: type: String description: (Required) The ARN for the IAM role that permits RDS to send enhanced monitoring metrics to Amazon CloudWatch Logs. allowedPattern: ^arn:(aws[a-zA-Z-]*)?:iam::\d{12}:role/[a-zA-Z0-9+=,.@_/-]+$Verify parameter alignment in the triggering playbook
Check theAFSBP_RDS.6.yamldocument that calls your remediation runbook. Ensure that when it passes the IAM role ARN toASR-EnableEnhancedMonitoringOnRDSInstance, it's using the correctMonitoringRoleArnparameter name (revert any corresponding renames here if you made them).Redeploy your Terraform resources
Once the parameter names are back in sync with the RDS API requirements, re-run your Terraform apply. The "Unknown property" error should no longer appear, as SSM will correctly map the parameter to the underlying API call.
A Quick Note on Customizing Official Solutions
AWS's Security Hub Automated Response and Remediation solution's SSM documents are tightly integrated with AWS service APIs. Parameter names, input structures, and logic are all built to match API expectations. Tweaking parameter names without updating the corresponding API call logic in the document will almost always lead to errors like this. If you need to customize the solution, focus on modifying logic flows or adding additional steps rather than renaming core API-bound parameters.
内容的提问来源于stack exchange,提问作者Justin Lawhorne

