本文介绍: 其次EC的instance role必须有一个叫“AmazonSSMManagedInstanceCore”的策略。首先只有特定版本的OS会默认附带SSM Agent。

首先只有特定版本的OS会默认附带SSM Agent。

预安装了 SSM Agent 的 Amazon Machine Images(AMIs) – AWS Systems Manager

其次EC的instance role必须有一个叫“AmazonSSMManagedInstanceCore”的策略

 

如何给IAM User赋权,让他们可以使用SSM会话

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "ec2:DescribeInstanceAttribute",
                "ec2:DescribeVolumeAttribute"
            ],
            "Resource": [
                "arn:aws-cn:ec2:*:xxxxxxxxx2:instance/*",
                "arn:aws-cn:ec2:*:xxxxxxxxx2:volume/*"
            ]
        },
        {
            "Sid": "VisualEditor1",
            "Effect": "Allow",
            "Action": [
                "ec2:DescribeInstances",
                "ec2:DescribeVolumeStatus",
                "ssm:DescribeInstanceInformation",
                "ec2:DescribeTags",
                "ec2:DescribeVolumes",
                "ec2:DescribeInstanceStatus"
            ],
            "Resource": "*"
        },
        {
            "Sid": "VisualEditor2",
            "Effect": "Allow",
            "Action": [
                "ssm:GetConnectionStatus",
                "ssm:StartSession"
            ],
            "Resource": "arn:aws-cn:ec2:*:xxxxxxxxx2:instance/*"
        },
        {
            "Sid": "VisualEditor3",
            "Effect": "Allow",
            "Action": [
                "ec2:StartInstances",
                "ec2:StopInstances"
            ],
            "Resource": "arn:aws-cn:ec2:*:xxxxxxxxx2:instance/*"
        }
    ]
}

原文地址:https://blog.csdn.net/rav009/article/details/134719834

本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任

如若转载,请注明出处:http://www.7code.cn/show_18711.html

如若内容造成侵权/违法违规/事实不符,请联系代码007邮箱suwngjj01@126.com进行投诉反馈,一经查实,立即删除

发表回复

您的电子邮箱地址不会被公开。 必填项已用 * 标注