Configuration and patching
Using Systems Manager to patch, configure, access and inventory EC2 and on-premises servers at scale, and building golden AMIs with EC2 Image Builder.
Exam tasks: 2.1 (configuration management), 2.3 (patching and secure remote access), 3.2 (improve security and operations of existing fleets)
The decision: do you fix servers where they run (patch and configure in place with Systems Manager), or replace them with a freshly built image? And how do you reach them without opening inbound ports?
Which Systems Manager capability?
Prerequisites for a managed node
- The SSM Agent (preinstalled on most AWS-provided AMIs).
- Permissions: an instance profile with
AmazonSSMManagedInstanceCore, or Default Host Management Configuration, which grants them account-wide without touching instance profiles. - A network path to the Systems Manager endpoints: internet or NAT, or interface VPC endpoints (
ssm,ssmmessages,ec2messages) for private subnets.
Instances missing from Fleet Manager
When instances don't show up as managed nodes, the cause is almost always one of the three prerequisites: no agent, no IAM permissions, or no route to the endpoints from a private subnet. Security groups don't need inbound rules. The agent connects outbound.
Capabilities side by side
| Capability | What it does | Typical exam signal |
|---|---|---|
| Patch Manager | Scans or installs patches using a patch baseline, via the AWS-RunPatchBaseline document | "Patch 800 Windows and Linux servers monthly and report compliance" |
| Maintenance windows | Schedule with a duration and cutoff, targets and tasks (Run Command, Automation, Lambda, Step Functions) | "Only between 02:00 and 04:00 on Sundays" |
| Run Command | One-off command across targets, with concurrency and error-threshold rate controls | "Restart the agent on every tagged instance now" |
| State Manager | Associations that reapply a document on a schedule to keep a desired state | "Make sure the CloudWatch agent is always installed and configured" |
| Automation | Runbooks with steps, approvals, branching and AWS API calls. Runs across accounts and Regions | "Stop, snapshot and resize an instance" or remediation from Config |
| Session Manager | Browser or CLI shell and port forwarding over the agent, with sessions logged to S3 or CloudWatch Logs | "Remove bastion hosts and close port 22" |
| Parameter Store | Hierarchical config values, SecureString encrypted with KMS | "Store DB endpoints and flags per environment" |
| Inventory | Collects installed apps, patches, files and network config. Resource Data Sync aggregates it into S3 | "Query installed software across all accounts with Athena" |
| Quick Setup | Deploys recommended configurations (patch policies, Inventory, DHMC) across an organization | "Enable patching for every account and Region with the least effort" |
Patch Manager in detail
- A patch baseline decides which patches are approved: by classification and severity, with an auto-approval delay (for example 7 days after release), plus explicit approved and rejected lists.
- AWS provides predefined baselines per OS. Create a custom one when you need a delay, exceptions or non-security updates.
- Patch policies created through Quick Setup apply baselines and schedules across the organization. The older approach tags instances with a patch group and registers the group with a baseline.
- Operation
Scanreports compliance only.Installpatches and, by default, reboots if needed. - Compliance results feed Systems Manager Compliance, AWS Config and Security Hub.
Exam signal
"Test patches in dev before prod" usually means one baseline with an approval delay, and dev's maintenance window running days before prod's. Both environments then install the same approved set.
Session Manager instead of SSH
- No inbound ports, no key pairs, no bastion host. Access is controlled with IAM, and can be limited by tag.
- Every session can be logged to S3 or CloudWatch Logs and recorded in CloudTrail. Session data can be encrypted with a KMS key.
- Port forwarding reaches an RDS database or internal web UI through a managed instance.
- Works in private subnets through the VPC endpoints listed above.
EC2 Instance Connect is not the same
EC2 Instance Connect still pushes an SSH key and uses port 22 (or an Instance Connect Endpoint). If the question says "no inbound ports" and "log every command", Session Manager is the answer.
Parameter Store tiers
| Standard | Advanced | |
|---|---|---|
| Max value size | 4 KB | 8 KB |
| Parameters per account and Region | 10,000 | 100,000 |
| Parameter policies (expiration, notifications) | No | Yes |
| Cost | No storage charge | Charged per parameter |
For secrets that need automatic rotation, use Secrets Manager instead. See secrets and least privilege.
Hybrid and on-premises servers
- Create an IAM service role for Systems Manager.
- Create a hybrid activation, which returns an activation code and ID.
- Install the agent on each server and register it with the code and ID.
- The servers appear as managed nodes with an
mi-prefix, and use the same Patch Manager, Run Command and Inventory as EC2.
Session Manager on on-premises nodes needs the advanced-instances tier. Pair hybrid activations with hybrid connectivity and private endpoints if the traffic must not use the internet.
Golden AMIs with EC2 Image Builder
Patching in place drifts over time. Immutable infrastructure rebuilds the image and replaces instances instead.
- An image recipe is a base image plus components (install, configure, harden with CIS or STIG components).
- Tests run on a temporary instance before the image is published.
- Distribution settings copy the AMI to other Regions, share it with accounts or an organization, and can update a launch template.
- A pipeline runs on a schedule or when the base image gets updates. An Auto Scaling group instance refresh then rolls the new AMI out.
- The same service builds container images and pushes them to ECR.
Exam signal
"Every new instance must launch already patched and hardened" points to an Image Builder pipeline. "Patch the instances that are running now" points to Patch Manager. Many good answers use both.
Legacy: use AWS Systems Manager (State Manager, Automation) or IaC instead
AWS OpsWorks (Stacks, Chef Automate and Puppet Enterprise) reached end of life in 2024. If an answer offers OpsWorks for Chef or Puppet configuration management, treat it as outdated. Systems Manager can still run Chef recipes, Ansible playbooks and PowerShell DSC through State Manager documents.
Scenarios
A Quick Setup patch policy applies baselines and schedules organization-wide, and reports compliance centrally. Lambda in each account works but is custom code in 40 accounts. A weekly AMI depends on every team redeploying, and Config rules only report compliance without installing anything.
Session Manager needs the agent to reach Systems Manager (the endpoints do that without internet access), IAM permissions for the instance, and logging configured in the Session Manager preferences. No inbound port or SSH key is used. A NAT gateway would work too, but it's unnecessary once the endpoints exist, and it adds an internet path.
Further reading
Deployment strategies
All-at-once, rolling, immutable, blue/green, canary and linear deployments, how CodeDeploy, Elastic Beanstalk and CloudFormation implement them, and how to roll back safely.
DDoS and edge security
Shield Standard and Advanced, AWS WAF rules, Firewall Manager, CloudFront and Global Accelerator as the edge, and where Network Firewall and security groups fit.