AWS SSM Session Manager Overview

Untitled

Untitled

Example IAM Policy for SSM Session Manager Access

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "ssm:StartSession",
      "Resource": "arn:aws:ec2:*:*:instance/*",
      "Condition": {
        "StringEquals": {
          "ec2:ResourceTag/environment": "dev"
        }
      }
    }
  ]
}

This policy allows a user to start a session with any EC2 instance tagged as a development environment and to write logs to a specified S3 bucket and CloudWatch Logs.