Skip to main content

How to connect to EC2 instance (without private key) using SSM Session Manager?

Run the following AWS CLI commands:

$ aws ec2 run-instances --image-id <Id-of-AMI-with-SSM-Agent-pre-installed> --subnet-id <subnet-id> --instance-type <instance-type> --associate-public-ip-address

$ aws iam create-role --role-name <role-name> --assume-role-policy-document '{"Version":"2012-10-17","Statement":{"Effect":"Allow","Principal":{"Service":"ec2.amazonaws.com"},"Action":"sts:AssumeRole"}}'

Note: The command above has inline JSON. Run such commands only from bash (not from cmd/powershell).

$ aws iam attach-role-policy --role-name <role-name> --policy-arn <ARN-of-AmazonSSMManagedInstanceCore-Policy>

$ aws iam create-instance-profile --instance-profile-name <instance-profile-name>

$ aws iam add-role-to-instance-profile --role-name <role-name> --instance-profile-name <instance-profile-name>

$ aws ec2 associate-iam-instance-profile --instance-id <ec2-instance-id> --iam-instance-profile Name=<instance-profile-name>

$ aws ec2 describe-iam-instance-profile-associations

$ aws ssm start-session --target <ec2-instance-id>

Note: Install Session Manager - https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager-working-with-install-plugin.html#install-plugin-debian

If the EC2 instances are in a private subnet, you can do the following:

- Route traffic to internet through a NAT GW

- If you don't want to use NAT GW, add the following Interface VPC endpoints:

com.amazonaws.eu-west-2.ssm

com.amazonaws.eu-west-2.ssmmessages

com.amazonaws.eu-west-2.ec2messages

Link the subnets and Security Groups to these VPC endpoints. The Security Groups linked to these VPC endpoints should allow outbound HTTPS traffic to SSM. 


Comments

Popular posts from this blog

GoLang - How to check if key exists in map?

package main import "fmt" var m map[string]string func main() { m = make(map[string]string) m["foo"] = "abc" if val, ok := m["foo"]; ok { fmt.Println("foo found -", val) } else { fmt.Println("foo not found") } if val, ok := m["bar"]; ok { fmt.Println("bar found -", val) } else { fmt.Println("bar not found") } } Output: foo found - abc bar not found

How to delete commits in Git?

Suppose you have 3 commits with SHAs as follows: HEAD~0 --> Commit 3 ccccccc HEAD~1 --> Commit 2 bbbbbbb HEAD~2 --> Commit 1 aaaaaaa If you want to remove the last two commits (i.e., commits 2 and 3) and make Commit 1 as the latest commit, run the following commands: git reset --hard aaaaaaa git push origin HEAD --force Now, the commit history would be as follows: HEAD~0 --> Commit 1 aaaaaaa

How to fix the error - botocore.exceptions.ProfileNotFound: The config profile (AnyProfileName) could not be found?

This occurs when you do aws configure in cmd. It is caused by setting the following environment variable: AWS_PROFILE = AnyProfileName Removing this environment variable is the fix. After removing, if you do aws configure , aws would be configured for the default profile rather than AnyProfileName .