# AWS Systems Manager

> AWS Systems Manager (SSM) manages servers at scale: Session Manager shell access without SSH, Parameter Store, Patch Manager, Run Command and Automation.

- Source: https://www.itwonderlab.com/aws-systems-manager/
- Published: 2026-10-05
- Updated: 2026-10-05
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**AWS Systems Manager** (SSM) is a collection of capabilities to operate and manage [EC2](https://www.itwonderlab.com/aws-ec2/) instances and on-premises servers. It works through the **SSM Agent**, which is installed in the most common AMIs, and needs an [IAM](https://www.itwonderlab.com/aws-iam/) instance profile (for example with the managed policy `AmazonSSMManagedInstanceCore`) and network access to the SSM endpoints.

### Main capabilities

- **Session Manager**: an interactive shell or port forwarding to an instance through the AWS API, **without opening port 22**, without [SSH keys](https://www.itwonderlab.com/public-key-authentication/) and with every session logged in [CloudTrail](https://www.itwonderlab.com/aws-cloudtrail/) and optionally in [S3](https://www.itwonderlab.com/aws-s3/) or [CloudWatch](https://www.itwonderlab.com/aws-cloudwatch/). It replaces bastion hosts and [SSH](https://www.itwonderlab.com/ssh/) access from the Internet.
- **Parameter Store**: hierarchical configuration data and secrets (as `SecureString`, encrypted with [KMS](https://www.itwonderlab.com/aws-kms/)), with versions and IAM access control. For secrets with automatic rotation see [Secrets Manager](https://www.itwonderlab.com/aws-secrets-manager/).
- **Run Command**: runs commands on many instances at once, without SSH.
- **Patch Manager**: defines and schedules patch baselines and reports compliance.
- **State Manager** and **Automation**: keep a desired configuration and run runbooks, for example to create an [AMI](https://www.itwonderlab.com/aws-ami/) or to restart services.
- **Inventory**, **Fleet Manager**, **Maintenance Windows** and **OpsCenter** complete the service.

### Pricing

Most capabilities are free; Parameter Store advanced parameters, some Automation features and Session Manager on-premises instances (advanced tier) have a cost. See the [Systems Manager pricing](https://aws.amazon.com/systems-manager/pricing/).

### With Terraform

The resources include `aws_ssm_parameter`, `aws_ssm_document`, `aws_ssm_association`, `aws_ssm_maintenance_window` and `aws_ssm_patch_baseline`; the data source `aws_ssm_parameter` also reads the latest AMI ID published by AWS.

See also: [Cloud-init](https://www.itwonderlab.com/cloud-init/), [Ansible](https://www.itwonderlab.com/tutorials/ansible/) for configuration management.
