"Tunnel created using SSM only allows single connection to destination port" - https://forums.aws.amazon.com/thread.jspa?threadID=314882&ts...
This has been sitting open in the support forums unanswered for over two months :/
1) Is logging for access from CLI finally supported?
2) Can I setup which shell is used?
3) Are logs readable when I switch to something else than sh?
4) Is U2F supported (awscli question)
Once all of these are fixed, then it can be possible to claim that SSM solves these issues. Otherwise it’s nothing more than for adhoc usage.
we have some regulatory requirements that require us to use hardware tokens for 2FA access to servers.
2. what about SSH tunnels ?
If you're doing a federated login with Okta or another provider, you need to set up the hardware MFA there.
There is SSH tunneling support as well, will add an update on that soon.