aws.ssm-managed-instance
Instances managed by ssm, both ec2 (i-) and hybrid (mi-) instances.
Tags are fetched via the ssm tag apis for hybrid instances and from ec2 for ec2 instances, so tag filters work across the whole resource population. The tag actions only apply to hybrid instances, as the ssm tag apis don’t support ec2 instances; use the aws.ec2 resource to manage those tags.
- example:
policies:
- name: ssm-hybrid-instance-untagged
resource: aws.ssm-managed-instance
filters:
- type: value
key: InstanceId
op: glob
value: "mi-*"
- "tag:Owner": absent
actions:
- type: tag
key: Owner
value: unknown
Filters
Actions
send-command
Run an SSM Automation Document on an instance.
- Example:
Find ubuntu 18.04 instances are active with ssm.
policies:
- name: ec2-osquery-install
resource: ec2
filters:
- type: ssm
key: PingStatus
value: Online
- type: ssm
key: PlatformName
value: Ubuntu
- type: ssm
key: PlatformVersion
value: 18.04
actions:
- type: send-command
command:
DocumentName: AWS-RunShellScript
Parameters:
commands:
- wget https://pkg.osquery.io/deb/osquery_3.3.0_1.linux.amd64.deb
- dpkg -i osquery_3.3.0_1.linux.amd64.deb
properties:
command:
type: object
type:
enum:
- send-command
required:
- command
Permissions - ssm:SendCommand