AWS Systems Manager
AWS Systems Manager (SSM) is a bundle of operational tools for managing EC2 instances and on-prem servers. It started as a config store and a way to run commands on instances. It has grown into about twenty loosely related features under one console page. Most people use three or four of them.
The foundation: the SSM Agent
Every managed instance runs the SSM Agent. It is preinstalled on Amazon Linux, Ubuntu AMIs from AWS, and Windows AMIs. The agent polls SSM over HTTPS (outbound only). This is the key architectural fact: SSM never connects inbound to your instance. That means no inbound security group rules, no bastion, no public IP needed.
For the agent to work, the instance needs:
- An IAM instance profile with the
AmazonSSMManagedInstanceCorepolicy. - Outbound HTTPS to the SSM endpoints. Either a NAT gateway or VPC endpoints for
ssm,ssmmessagesandec2messages. VPC endpoints let fully private subnets work with no internet access at all.
Non-EC2 machines (on-prem, Proxmox VMs, other clouds) can be enrolled as “hybrid managed nodes” with a hybrid activation. They show up with an mi- prefix instead of i-. Standard pricing covers a small number; beyond that it is per-node per-hour under the Advanced tier.
The features that matter
Session Manager. Interactive shell into an instance through the SSM channel. Replaces SSH. No keys, no open port 22, access controlled by IAM, every session can be logged to CloudWatch or S3. Also does port forwarding, which is how you reach a private RDS instance from your laptop without a bastion:
aws ssm start-session --target i-0abc123 \
--document-name AWS-StartPortForwardingSessionToRemoteHost \
--parameters host=mydb.xyz.rds.amazonaws.com,portNumber=5432,localPortNumber=5432
You can also route real SSH through it with a ProxyCommand in ~/.ssh/config, which is what Ansible needs. Ansible has a native aws_ssm connection plugin as well, but the SSH-over-SSM proxy is more reliable.
Parameter Store. A key-value store for configuration and secrets. Hierarchical paths (/prod/app/db_password), string or SecureString (KMS encrypted), versioned. Standard tier is free up to 10,000 parameters and 4 KB each. It overlaps with Secrets Manager. The difference: Secrets Manager costs money per secret, rotates credentials automatically and integrates with RDS. Parameter Store is free and does not rotate. For app config and static secrets, use Parameter Store. For database credentials you want rotated, use Secrets Manager.
Run Command. Execute a script or a predefined “document” across many instances at once, selected by tag or ID. Output goes to S3 or CloudWatch. Useful for one-off fleet operations. Ansible is usually the better tool if you already have it.
Patch Manager. Scheduled OS patching with baselines (which severities, which packages, how long after release) and maintenance windows. Reports compliance. This is the feature people actually adopt SSM for in regulated environments because it produces the audit evidence.
State Manager. Enforces a desired configuration on a schedule by repeatedly applying a document. Think of it as a weak Ansible pull mode. Commonly used just to keep the SSM Agent and CloudWatch agent updated.
Automation. Runbooks for multi-step workflows: create an AMI, patch it, run tests, promote it. Can call Lambda, approval steps, and other AWS APIs. Good for golden-AMI pipelines. Verbose YAML.
The rest, briefly
- Inventory: collects installed packages, running services and network config from every node into a queryable table.
- Fleet Manager: web UI over instances, including a file browser and Windows registry editor.
- Documents: the JSON/YAML definitions that Run Command, Automation and State Manager execute. AWS ships hundreds; you can write your own.
- OpsCenter, Incident Manager, Change Manager: ITSM-style ticketing and change approval. Rarely used outside large enterprises.
- Application Manager, AppConfig: AppConfig is feature flags and dynamic config with validation and gradual rollout. It is separately useful and separately billed.
- Distributor: package installation across a fleet. Mostly used for agents.
- Quick Setup: wizard that wires up the IAM roles, agent updates and inventory across an account or organisation.
How to use it with your stack
- Terraform:
aws_ssm_parameterfor config,aws_iam_roleplusaws_iam_instance_profilewith the managed policy,aws_vpc_endpointfor the three endpoints if subnets are private. - Ansible: SSH over SSM ProxyCommand, inventory from
amazon.aws.aws_ec2plugin filtered by tag. - Apps: read Parameter Store at startup with boto3
get_parameters_by_path. Cache it. Do not call it per request. - Proxmox: hybrid activation works, but for a homelab it is not worth the setup unless you want the single pane of glass.
What to actually take away
Session Manager and Parameter Store are the two features worth adopting on every AWS account, regardless of size. Patch Manager if you need compliance reporting. Ignore the rest until a concrete need shows up. The feature set changes a few times a year, so check the docs before relying on a specific limit or price.
Back to top