AWS Systems Manager

· 1 min read · AWS

AWS Systems Manager (SSM) is a collection of capabilities to operate and manage EC2 instances and on-premises servers. It works through the SSM Agent, which is installed in the most common AMIs, and needs an IAM instance profile (for example with the managed policy AmazonSSMManagedInstanceCore) and network access to the SSM endpoints.

Main capabilities #

  • Session Manager: an interactive shell or port forwarding to an instance through the AWS API, without opening port 22, without SSH keys and with every session logged in CloudTrail and optionally in S3 or CloudWatch. It replaces bastion hosts and SSH access from the Internet.
  • Parameter Store: hierarchical configuration data and secrets (as SecureString, encrypted with KMS), with versions and IAM access control. For secrets with automatic rotation see Secrets Manager.
  • Run Command: runs commands on many instances at once, without SSH.
  • Patch Manager: defines and schedules patch baselines and reports compliance.
  • State Manager and Automation: keep a desired configuration and run runbooks, for example to create an AMI or to restart services.
  • Inventory, Fleet Manager, Maintenance Windows and OpsCenter complete the service.

Pricing #

Most capabilities are free; Parameter Store advanced parameters, some Automation features and Session Manager on-premises instances (advanced tier) have a cost. See the Systems Manager pricing.

With Terraform #

The resources include aws_ssm_parameter, aws_ssm_document, aws_ssm_association, aws_ssm_maintenance_window and aws_ssm_patch_baseline; the data source aws_ssm_parameter also reads the latest AMI ID published by AWS.

See also: Cloud-init, Ansible for configuration management.

More tutorials that use Systems Manager

#AWS #AWS EC2 #SSH