Asterrr's Handbook

Configuration and patching

Using Systems Manager to patch, configure, access and inventory EC2 and on-premises servers at scale, and building golden AMIs with EC2 Image Builder.

Exam tasks: 2.1 (configuration management), 2.3 (patching and secure remote access), 3.2 (improve security and operations of existing fleets)

The decision: do you fix servers where they run (patch and configure in place with Systems Manager), or replace them with a freshly built image? And how do you reach them without opening inbound ports?

Which Systems Manager capability?

Prerequisites for a managed node

  • The SSM Agent (preinstalled on most AWS-provided AMIs).
  • Permissions: an instance profile with AmazonSSMManagedInstanceCore, or Default Host Management Configuration, which grants them account-wide without touching instance profiles.
  • A network path to the Systems Manager endpoints: internet or NAT, or interface VPC endpoints (ssm, ssmmessages, ec2messages) for private subnets.

Instances missing from Fleet Manager

When instances don't show up as managed nodes, the cause is almost always one of the three prerequisites: no agent, no IAM permissions, or no route to the endpoints from a private subnet. Security groups don't need inbound rules. The agent connects outbound.

Capabilities side by side

CapabilityWhat it doesTypical exam signal
Patch ManagerScans or installs patches using a patch baseline, via the AWS-RunPatchBaseline document"Patch 800 Windows and Linux servers monthly and report compliance"
Maintenance windowsSchedule with a duration and cutoff, targets and tasks (Run Command, Automation, Lambda, Step Functions)"Only between 02:00 and 04:00 on Sundays"
Run CommandOne-off command across targets, with concurrency and error-threshold rate controls"Restart the agent on every tagged instance now"
State ManagerAssociations that reapply a document on a schedule to keep a desired state"Make sure the CloudWatch agent is always installed and configured"
AutomationRunbooks with steps, approvals, branching and AWS API calls. Runs across accounts and Regions"Stop, snapshot and resize an instance" or remediation from Config
Session ManagerBrowser or CLI shell and port forwarding over the agent, with sessions logged to S3 or CloudWatch Logs"Remove bastion hosts and close port 22"
Parameter StoreHierarchical config values, SecureString encrypted with KMS"Store DB endpoints and flags per environment"
InventoryCollects installed apps, patches, files and network config. Resource Data Sync aggregates it into S3"Query installed software across all accounts with Athena"
Quick SetupDeploys recommended configurations (patch policies, Inventory, DHMC) across an organization"Enable patching for every account and Region with the least effort"

Patch Manager in detail

  • A patch baseline decides which patches are approved: by classification and severity, with an auto-approval delay (for example 7 days after release), plus explicit approved and rejected lists.
  • AWS provides predefined baselines per OS. Create a custom one when you need a delay, exceptions or non-security updates.
  • Patch policies created through Quick Setup apply baselines and schedules across the organization. The older approach tags instances with a patch group and registers the group with a baseline.
  • Operation Scan reports compliance only. Install patches and, by default, reboots if needed.
  • Compliance results feed Systems Manager Compliance, AWS Config and Security Hub.

Exam signal

"Test patches in dev before prod" usually means one baseline with an approval delay, and dev's maintenance window running days before prod's. Both environments then install the same approved set.

Session Manager instead of SSH

  • No inbound ports, no key pairs, no bastion host. Access is controlled with IAM, and can be limited by tag.
  • Every session can be logged to S3 or CloudWatch Logs and recorded in CloudTrail. Session data can be encrypted with a KMS key.
  • Port forwarding reaches an RDS database or internal web UI through a managed instance.
  • Works in private subnets through the VPC endpoints listed above.

EC2 Instance Connect is not the same

EC2 Instance Connect still pushes an SSH key and uses port 22 (or an Instance Connect Endpoint). If the question says "no inbound ports" and "log every command", Session Manager is the answer.

Parameter Store tiers

StandardAdvanced
Max value size4 KB8 KB
Parameters per account and Region10,000100,000
Parameter policies (expiration, notifications)NoYes
CostNo storage chargeCharged per parameter

For secrets that need automatic rotation, use Secrets Manager instead. See secrets and least privilege.

Hybrid and on-premises servers

  1. Create an IAM service role for Systems Manager.
  2. Create a hybrid activation, which returns an activation code and ID.
  3. Install the agent on each server and register it with the code and ID.
  4. The servers appear as managed nodes with an mi- prefix, and use the same Patch Manager, Run Command and Inventory as EC2.

Session Manager on on-premises nodes needs the advanced-instances tier. Pair hybrid activations with hybrid connectivity and private endpoints if the traffic must not use the internet.

mi-
Prefix of on-premises managed nodes registered with a hybrid activation
4 KB / 8 KB
Parameter Store value size, standard and advanced tiers
0
Inbound ports Session Manager needs

Golden AMIs with EC2 Image Builder

Patching in place drifts over time. Immutable infrastructure rebuilds the image and replaces instances instead.

  • An image recipe is a base image plus components (install, configure, harden with CIS or STIG components).
  • Tests run on a temporary instance before the image is published.
  • Distribution settings copy the AMI to other Regions, share it with accounts or an organization, and can update a launch template.
  • A pipeline runs on a schedule or when the base image gets updates. An Auto Scaling group instance refresh then rolls the new AMI out.
  • The same service builds container images and pushes them to ECR.

Exam signal

"Every new instance must launch already patched and hardened" points to an Image Builder pipeline. "Patch the instances that are running now" points to Patch Manager. Many good answers use both.

Legacy: use AWS Systems Manager (State Manager, Automation) or IaC instead

AWS OpsWorks (Stacks, Chef Automate and Puppet Enterprise) reached end of life in 2024. If an answer offers OpsWorks for Chef or Puppet configuration management, treat it as outdated. Systems Manager can still run Chef recipes, Ansible playbooks and PowerShell DSC through State Manager documents.

Scenarios

Scenario
A company has 1,500 EC2 instances in 40 accounts in AWS Organizations, across 3 Regions. Security wants critical OS patches installed weekly on every instance and a single compliance view, with the least operational effort. What should the architect do?
Scenario · choose 3
A financial company must remove all bastion hosts. Engineers need shell access to instances in private subnets that have no internet route, and every command must be logged. Which THREE actions are required?

Further reading

On this page