{"repo":"qoomon/aws-ssm-ssh-proxy-command","free":true,"listed":false,"github":"https://github.com/qoomon/aws-ssm-ssh-proxy-command","clone":"git clone https://github.com/qoomon/aws-ssm-ssh-proxy-command.git","description":"AWS SSM SSH Proxy Command","language":"Shell","stars":263,"topics":["ssh","aws-cli","aws-ssm","ssh-proxy-command","ec2","aws","security","managed-instance","proxy-command"],"license":"MIT","category":"security-tools","readme_excerpt":"aws-ssm-ssh-proxy-command Open an SSH connection to your AWS SSM connected instances without the need to open any ssh port in you security groups. [!Tip] If you only need to connect to AWS EC2 instances you could use the ec2-instance-connect variant of this proxy command. This variant allows you to manage wich IAM identity can connect to which OS user on the target instance. See EC2 Only Variant Prerequisits - Local Setup - Install AWS CLI - AWS Docs - MacOS brew install awscli - Install AWS CLI Session Manager Plugin - AWS Docs - MacOS brew install session-manager-plugin - Install the SSM SSH Proxy Command Script - Linux & MacOS - Copy aws-ssm-ssh-proxy-command.sh into /.ssh/aws-ssm-ssh-proxy-command.sh - Ensure it is executable ( chmod +x /.ssh/aws-ssm-ssh-proxy-command.sh ) - Windows - Copy aws-ssm-ssh-proxy-command.ps1 into /.ssh/aws-ssm-ssh-proxy-command.ps1 - Ensure you are allowed to execute powershell scripts (see Set-ExecutionPolicy command) - recommended Setup SSH Config - Add ssh config entry AWS instances to your /.ssh/config . - Linux & MacOS - Windows - Adjust IdentityFile and corresponding publickey (last argument of ProxyCommand ) if needed. - AWS IAM Setup - Ensure IAM Permissions for Your IAM Identity - IAM Policy Template - ssm:StartSession for DocumentName: AWS-StartSSHSession and Target Instance - AWS Documentation - ssm:SendCommand for DocumentName: AWS-RunShellScript and Target Instance - AWS Documentation - Target Instance Setup - Ensure IAM Permission","default_branch":null,"files":null,"tree":[],"storefront":"/r/qoomon","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/qoomon/aws-ssm-ssh-proxy-command/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}