Connecting to EC2 with Session Manager (No SSH Required)

Connecting to EC2 with Session Manager (No SSH Required)

Opening a shell on an EC2 instance through Systems Manager's Session Manager, with no SSH keys, bastion host, or open port 22 required.

Takahiro Iwasa
2 min read

Systems Manager - Session Manager provides shell access to EC2 instances without SSH:

  • No SSH keys: Eliminates the need to manage and secure SSH keys.
  • No bastion hosts: Removes the requirement for intermediary servers to access EC2 instances.
  • No inbound rules on port 22: Improves security by avoiding open ports in your security group.

Building

Session Manager requires an IAM role with the AmazonSSMManagedInstanceCore policy attached to the EC2 instance (line 30).

template.yaml
AWSTemplateFormatVersion: 2010-09-09
Resources:
EC2:
Type: AWS::EC2::Instance
Properties:
IamInstanceProfile: !Ref InstanceProfile
ImageId: ami-0f310fced6141e627
InstanceType: t3.small
SecurityGroups:
- !Ref SecurityGroup
InstanceProfile:
Type: AWS::IAM::InstanceProfile
Properties:
Path: /
Roles:
- !Ref IamRole
IamRole:
Type: AWS::IAM::Role
Properties:
AssumeRolePolicyDocument:
Version: 2012-10-17
Statement:
- Effect: Allow
Principal:
Service: ec2.amazonaws.com
Action: sts:AssumeRole
ManagedPolicyArns:
- arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore
RoleName: ec2-role
SecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Example
GroupName: ec2-security-group
SecurityGroupIngress:
- CidrIp: 0.0.0.0/0
FromPort: 443
IpProtocol: tcp
ToPort: 443
ℹ️ Note

If your EC2 instances are in private subnets, set up the following VPC endpoints:

  • com.amazonaws.region.ssm
  • com.amazonaws.region.ec2messages
  • com.amazonaws.region.ssmmessages

Refer to the official knowledge for more details.

Deploy the stack:

Terminal window
aws cloudformation deploy \
--template-file template.yaml \
--stack-name ec2-session-manager \
--capabilities CAPABILITY_NAMED_IAM

Testing

A session with the instance can be started with:

Terminal window
aws ssm start-session --target i-xxxxxxxxxxxxxxxxx

The output will indicate a successful login:

Starting session with SessionId: your-session-id
sh-4.2$

Cleaning Up

Delete the stack to remove the provisioned resources:

Terminal window
aws cloudformation delete-stack --stack-name ec2-session-manager

Conclusion

Attaching the AmazonSSMManagedInstanceCore managed policy to the EC2 instance role was enough to open a shell session with aws ssm start-session, with no SSH key pair or bastion host involved. That policy attachment is really the entire setup — the security group in this example only needs to allow outbound HTTPS rather than any inbound rule on port 22 — which is a meaningful reduction in what has to be managed and secured compared to a traditional SSH-based access pattern. The one prerequisite worth planning for is network reachability to the ssm, ec2messages, and ssmmessages endpoints: public subnets reach them without extra configuration, but private subnets need the corresponding VPC endpoints in place before the session will succeed.

About the author

Takahiro Iwasa

Takahiro Iwasa

Software Developer

This blog shares technical notes from hands-on projects—architecture, implementation, and AWS service integrations.