[1] https://docs.aws.amazon.com/systems-manager/latest/userguide...
[1] https://docs.aws.amazon.com/systems-manager/latest/userguide...
I've tried using it for development, and it was a terrible experience. The connections would hang all the time for no reason. I ended up starting an SSH session (via SSM) and done the port forwarding via that...
[0] https://docs.aws.amazon.com/systems-manager/latest/userguide...
Huge shameless plug for the coolness that is Session Manager, I can only think of a few scenarios where you wouldn't just prefer it over the alternatives. If you haven't played with it (or other SSM stuff), you totally should! It's cool and useful and easy and more or less free.
If you can make a good case for it, open a ticket or make a stink on the forums and there's a chance an engineer can be tasked to add it to their list of Officially Supported Platforms. This is how eg raspbian got added, though I don't know if the program is still running for adding platforms as it's been a few years.
If you're interested in more feedback, I'd be happy to share. As with many things AWS, there were some undocumented rougher edges that took some trial and error to figure. Although the end result was well worth it. Totally understand if you're not on HN to do that sort of thing, though.
e: or put an email in your profile and I'll even reach out!
Also can u restrict access to ssh through ssm to certain ips?
Maybe I might have missed these, so any help would be appreciated.
Technically there is, you can use federated login. Might not be very convenient, depending on your identity provider.
A solution I use, while not technically "not using access kys" is storing them in the system credential store with aws-vault [0]. Works on Windows, Linux and Mac. And you can combine this with multi factor auth.
> Also can u restrict access to ssh through ssm to certain ips?
Yes, with an IAM policy. The policy below requires connecting with an MFA and from a specific IP range. It only allows connecting to a specific instance.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": "ssm:StartSession",
"Resource": [
"arn:aws:ec2:eu-west-3:123123123123:instance/i-123123123123",
"arn:aws:ssm:eu-west-3::document/AWS-StartPortForwardingSession",
"arn:aws:ssm:eu-west-3::document/AWS-StartSSHSession"
],
"Condition": {
"IpAddress": {
"aws:SourceIp": "1.2.3.4/32"
},
"BoolIfExists": {
"aws:MultiFactorAuthPresent": "true"
}
}
}
]
}
[0] AWS Vault: https://github.com/99designs/aws-vault/