aws.ssm-managed-instance

Instances managed by ssm, both ec2 (i-) and hybrid (mi-) instances.

Tags are fetched via the ssm tag apis for hybrid instances and from ec2 for ec2 instances, so tag filters work across the whole resource population. The tag actions only apply to hybrid instances, as the ssm tag apis don’t support ec2 instances; use the aws.ec2 resource to manage those tags.

example:

policies:
  - name: ssm-hybrid-instance-untagged
    resource: aws.ssm-managed-instance
    filters:
      - type: value
        key: InstanceId
        op: glob
        value: "mi-*"
      - "tag:Owner": absent
    actions:
      - type: tag
        key: Owner
        value: unknown

Filters

Actions

send-command

Run an SSM Automation Document on an instance.

Example:

Find ubuntu 18.04 instances are active with ssm.

policies:
  - name: ec2-osquery-install
    resource: ec2
    filters:
      - type: ssm
        key: PingStatus
        value: Online
      - type: ssm
        key: PlatformName
        value: Ubuntu
      - type: ssm
        key: PlatformVersion
        value: 18.04
    actions:
      - type: send-command
        command:
          DocumentName: AWS-RunShellScript
          Parameters:
            commands:
              - wget https://pkg.osquery.io/deb/osquery_3.3.0_1.linux.amd64.deb
              - dpkg -i osquery_3.3.0_1.linux.amd64.deb
properties:
  command:
    type: object
  type:
    enum:
    - send-command
required:
- command

Permissions - ssm:SendCommand