AWS Systems Manager

AWS Systems Manager
Author

Benedict Thekkel

AWS Systems Manager (SSM) is a bundle of operational tools for managing EC2 instances and on-prem servers. It started as a config store and a way to run commands on instances. It has grown into about twenty loosely related features under one console page. Most people use three or four of them.

The foundation: the SSM Agent

Every managed instance runs the SSM Agent. It is preinstalled on Amazon Linux, Ubuntu AMIs from AWS, and Windows AMIs. The agent polls SSM over HTTPS (outbound only). This is the key architectural fact: SSM never connects inbound to your instance. That means no inbound security group rules, no bastion, no public IP needed.

For the agent to work, the instance needs:

Non-EC2 machines (on-prem, Proxmox VMs, other clouds) can be enrolled as “hybrid managed nodes” with a hybrid activation. They show up with an mi- prefix instead of i-. Standard pricing covers a small number; beyond that it is per-node per-hour under the Advanced tier.

The features that matter

Session Manager. Interactive shell into an instance through the SSM channel. Replaces SSH. No keys, no open port 22, access controlled by IAM, every session can be logged to CloudWatch or S3. Also does port forwarding, which is how you reach a private RDS instance from your laptop without a bastion:

aws ssm start-session --target i-0abc123 \
  --document-name AWS-StartPortForwardingSessionToRemoteHost \
  --parameters host=mydb.xyz.rds.amazonaws.com,portNumber=5432,localPortNumber=5432

You can also route real SSH through it with a ProxyCommand in ~/.ssh/config, which is what Ansible needs. Ansible has a native aws_ssm connection plugin as well, but the SSH-over-SSM proxy is more reliable.

Parameter Store. A key-value store for configuration and secrets. Hierarchical paths (/prod/app/db_password), string or SecureString (KMS encrypted), versioned. Standard tier is free up to 10,000 parameters and 4 KB each. It overlaps with Secrets Manager. The difference: Secrets Manager costs money per secret, rotates credentials automatically and integrates with RDS. Parameter Store is free and does not rotate. For app config and static secrets, use Parameter Store. For database credentials you want rotated, use Secrets Manager.

Run Command. Execute a script or a predefined “document” across many instances at once, selected by tag or ID. Output goes to S3 or CloudWatch. Useful for one-off fleet operations. Ansible is usually the better tool if you already have it.

Patch Manager. Scheduled OS patching with baselines (which severities, which packages, how long after release) and maintenance windows. Reports compliance. This is the feature people actually adopt SSM for in regulated environments because it produces the audit evidence.

State Manager. Enforces a desired configuration on a schedule by repeatedly applying a document. Think of it as a weak Ansible pull mode. Commonly used just to keep the SSM Agent and CloudWatch agent updated.

Automation. Runbooks for multi-step workflows: create an AMI, patch it, run tests, promote it. Can call Lambda, approval steps, and other AWS APIs. Good for golden-AMI pipelines. Verbose YAML.

The rest, briefly

How to use it with your stack

What to actually take away

Session Manager and Parameter Store are the two features worth adopting on every AWS account, regardless of size. Patch Manager if you need compliance reporting. Ignore the rest until a concrete need shows up. The feature set changes a few times a year, so check the docs before relying on a specific limit or price.

Back to top