You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Systems Manager自动化变量无法解析问题求助

问题解决思路与方案

问题根源

  1. Automation输出Selector路径错误:Run Command返回的结果中,PowerShell生成的JSON输出被嵌套在Output字段的转义字符串里,直接用validPassword作为Selector无法定位到目标值。
  2. PowerShell输出方式不规范:使用return可能引入额外输出,未压缩的JSON会产生多余换行/转义,干扰SSM的解析逻辑。

具体解决步骤

1. 修正AWS命令文档(SPIN_CheckPass)的PowerShell脚本

调整输出逻辑,确保仅返回干净的紧凑格式JSON:

{
  "schemaVersion": "2.2",
  "description": "Check Rotated Password",
  "parameters": {
    "password": {
      "type": "String",
      "description": "The new password used in the password rotation."
    }
  },
  "mainSteps": [
    {
      "action": "aws:runPowerShellScript",
      "name": "checkPassword",
      "inputs": {
        "runCommand": [
          "function checkPass {",
          "    param ($password)",
          "    $username = 'admin'",
          "    $computer = $env:COMPUTERNAME",
          "    Add-Type -AssemblyName System.DirectoryServices.AccountManagement",
          "    $obj = New-Object System.DirectoryServices.AccountManagement.PrincipalContext('machine',$computer)",
          "    # 保留原始布尔值,无需转为字符串",
          "    $result = $obj.ValidateCredentials($username, $password)",
          "    # 输出紧凑JSON,避免转义与换行问题",
          "    @{ validPassword = $result } | ConvertTo-Json -Compress | Write-Output",
          "}",
          "checkPass('{{password}}')"
        ],
        "runAsElevated": true
      }
    }
  ]
}
  • 用Write-Output替代return,确保仅输出JSON内容,避免额外返回值干扰
  • 添加-Compress参数生成紧凑JSON,减少转义与换行问题
  • 保留ValidateCredentials返回的布尔值,无需强制转为字符串

2. 修正Automation文档的步骤7输出Selector

使用JMESPath的from_string函数解析嵌套的JSON字符串,提取目标值:

- name: CheckNewPassword
    action: 'aws:runCommand'
    inputs:
      DocumentName: SPIN_CheckPass
      InstanceIds:
        - '{{nodeID}}'
      Parameters:
        password:
          - '{{GenerateNewPassword.newPassword}}'
    outputs:
      - Name: validPassword
        # 解析Output字段内的JSON字符串,再提取validPassword
        Selector: "from_string(Output).validPassword"
        Type: Boolean  # 匹配布尔值类型,若需字符串可改回String
      - Name: dataType
        Selector: "from_string(Output).dataType"
        Type: String
  - name: RecordPasswordStatus
    action: 'aws:invokeLambdaFunction'
    inputs:
      InvocationType: RequestResponse
      FunctionName: SPIN-CheckPassMetric
      InputPayload:
        passwordValid: '{{CheckNewPassword.validPassword}}'
        siteCode: '{{siteCode}}'
        num_failedValidation: 1
  • 将Selector改为from_string(Output).validPassword,解析嵌套在Output字段中的JSON字符串
  • 调整Type为Boolean,匹配返回的原生布尔值类型

额外排查点

  • 确认Run Command执行状态为Success,无报错信息
  • 检查PowerShell脚本是否存在额外输出(如警告、调试信息),可添加$ErrorActionPreference = 'SilentlyContinue'屏蔽无关输出
  • 确保目标实例的SSM Agent为最新版本,旧版本可能存在JSON解析兼容性问题

内容的提问来源于stack exchange,提问作者Jonathon Leonard

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 21:50:22