在AWS WAF CLI命令的JSON参数中使用Bash变量遇解析错误
I’ve seen plenty of folks run into this exact issue when building AWS CLI commands with Bash variables—your problem boils down to incorrect variable handling when manually constructing JSON for the --updates parameter, which ends up adding extra quotes or spaces around the DataId value and breaking the JSON structure.
Here are the most reliable ways to fix this:
1. Use jq to Generate Valid JSON (Recommended)
jq is a tool designed for working with JSON in shell scripts, and it’ll automatically handle escaping, quotes, and formatting to ensure your JSON is always valid. This is the safest approach, especially if your variables might contain special characters.
Example script:
# First, retrieve your required IDs and ChangeToken ipset_id=$(aws waf-regional get-ip-set --ip-set-id your-ipset-name --query IPSet.Id --output text) rule_id=$(aws waf-regional get-rule --rule-name your-rule-name --query Rule.Id --output text) change_token=$(aws waf-regional get-change-token --output text) target_ip="192.168.1.1/32" # Use jq to build the properly formatted updates JSON updates_json=$(jq -n \ --arg ip "$target_ip" \ --arg ipset "$ipset_id" \ --arg rule "$rule_id" \ '{ "Action": "INSERT", "ActivatedRule": { "Priority": 1, "RuleId": $rule, "Action": {"Type": "BLOCK"}, "OverrideAction": {"Type": "NONE"}, "Type": "IPMatch", "MatchPredicates": [ { "Negated": false, "Type": "IPMatch", "DataId": $ipset } ] } }') # Execute the update-rule command with the valid JSON aws waf-regional update-rule \ --rule-id "$rule_id" \ --change-token "$change_token" \ --updates "$updates_json"
Why this works:
jq takes care of all the JSON formatting rules—you don’t have to worry about mismatched quotes or accidental spaces. It’ll even escape special characters in your variables if needed.
2. Manually Escape Variables (For Simple Scenarios)
If you don’t want to use jq, you can manually construct the JSON string, but you need to be careful with how you embed variables. The key is to properly nest quotes to avoid extra whitespace or duplicate quotes.
Example:
ipset_id="your-ipset-id" rule_id="your-rule-id" change_token=$(aws waf-regional get-change-token --output text) target_ip="192.168.1.1/32" aws waf-regional update-rule \ --rule-id "$rule_id" \ --change-token "$change_token" \ --updates '[{ "Action": "INSERT", "ActivatedRule": { "Priority": 1, "RuleId": "'"$rule_id"'", "Action": {"Type": "BLOCK"}, "Type": "IPMatch", "MatchPredicates": [{ "Negated": false, "Type": "IPMatch", "DataId": "'"$ipset_id"'" }] } }]'
How this works:
The syntax '"$variable"' closes the outer double-quote, uses single-quotes to wrap the variable expansion (preventing word splitting or extra spaces), then reopens the double-quote to continue the JSON string. This ensures the variable’s value is inserted cleanly without extra quotes.
3. Troubleshooting Tip
Before running the AWS command, print out your generated JSON to verify it’s valid:
echo "$updates_json" | jq .
If jq throws an error, your JSON is malformed—go back and check how you’re handling variables. This quick check will save you time debugging the AWS CLI error.
内容的提问来源于stack exchange,提问作者naveen

