DEV Community

Angelo Alberto Santos
Angelo Alberto Santos

Posted on

Managing Private EC2 Instances Without Opening Port 22 Using AWS Systems Manager Session Manager

When we need to manage a Linux instance, SSH is usually one of the first options that comes to mind.

And there is nothing wrong with that. SSH is still a valid solution and can work through private networks, VPNs, Direct Connect, bastion hosts, and other controlled network paths.

But on AWS, there is another option: using AWS Systems Manager Session Manager to establish an administrative session without exposing an inbound port on the instance.

That leads to a more interesting question:

If there is no SSH connection coming into the EC2 instance, how does the administrator reach it?

To answer that, we first need to understand Session Manager before looking at any Terraform code.

What is AWS Systems Manager Session Manager?

Session Manager is a feature of AWS Systems Manager that allows you to establish interactive sessions with machines registered with Systems Manager as Managed Nodes.

For a Linux EC2 instance, the session mainly depends on two sides:

  • the administrator, authenticated and authorized through IAM;
  • the SSM Agent running inside the instance.

The administrator requests the session through Systems Manager. The agent maintains the required communication with AWS services and participates in establishing the session channel.

Because this flow does not start with a direct network connection from the administrator to the EC2 instance, there is no need to expose TCP/22 in the instance Security Group for this type of access.

That does not mean the instance can operate without connectivity.

The SSM Agent still needs to reach the required Systems Manager endpoints. We will come back to this because it is one of the most important architectural decisions in this design.

What changes compared to SSH?

Top comments (0)