AWS Systems Manager自动化变量无法解析问题求助
问题解决思路与方案
问题根源
- Automation输出Selector路径错误:Run Command返回的结果中,PowerShell生成的JSON输出被嵌套在
Output字段的转义字符串里,直接用validPassword作为Selector无法定位到目标值。 - PowerShell输出方式不规范:使用
return可能引入额外输出,未压缩的JSON会产生多余换行/转义,干扰SSM的解析逻辑。
具体解决步骤
1. 修正AWS命令文档(SPIN_CheckPass)的PowerShell脚本
调整输出逻辑,确保仅返回干净的紧凑格式JSON:
{ "schemaVersion": "2.2", "description": "Check Rotated Password", "parameters": { "password": { "type": "String", "description": "The new password used in the password rotation." } }, "mainSteps": [ { "action": "aws:runPowerShellScript", "name": "checkPassword", "inputs": { "runCommand": [ "function checkPass {", " param ($password)", " $username = 'admin'", " $computer = $env:COMPUTERNAME", " Add-Type -AssemblyName System.DirectoryServices.AccountManagement", " $obj = New-Object System.DirectoryServices.AccountManagement.PrincipalContext('machine',$computer)", " # 保留原始布尔值,无需转为字符串", " $result = $obj.ValidateCredentials($username, $password)", " # 输出紧凑JSON,避免转义与换行问题", " @{ validPassword = $result } | ConvertTo-Json -Compress | Write-Output", "}", "checkPass('{{password}}')" ], "runAsElevated": true } } ] }
- 用
Write-Output替代return,确保仅输出JSON内容,避免额外返回值干扰 - 添加
-Compress参数生成紧凑JSON,减少转义与换行问题 - 保留
ValidateCredentials返回的布尔值,无需强制转为字符串
2. 修正Automation文档的步骤7输出Selector
使用JMESPath的from_string函数解析嵌套的JSON字符串,提取目标值:
- name: CheckNewPassword action: 'aws:runCommand' inputs: DocumentName: SPIN_CheckPass InstanceIds: - '{{nodeID}}' Parameters: password: - '{{GenerateNewPassword.newPassword}}' outputs: - Name: validPassword # 解析Output字段内的JSON字符串,再提取validPassword Selector: "from_string(Output).validPassword" Type: Boolean # 匹配布尔值类型,若需字符串可改回String - Name: dataType Selector: "from_string(Output).dataType" Type: String - name: RecordPasswordStatus action: 'aws:invokeLambdaFunction' inputs: InvocationType: RequestResponse FunctionName: SPIN-CheckPassMetric InputPayload: passwordValid: '{{CheckNewPassword.validPassword}}' siteCode: '{{siteCode}}' num_failedValidation: 1
- 将
Selector改为from_string(Output).validPassword,解析嵌套在Output字段中的JSON字符串 - 调整
Type为Boolean,匹配返回的原生布尔值类型
额外排查点
- 确认Run Command执行状态为
Success,无报错信息 - 检查PowerShell脚本是否存在额外输出(如警告、调试信息),可添加
$ErrorActionPreference = 'SilentlyContinue'屏蔽无关输出 - 确保目标实例的SSM Agent为最新版本,旧版本可能存在JSON解析兼容性问题
内容的提问来源于stack exchange,提问作者Jonathon Leonard
相关产品推荐
相关产品推荐

