7. 7Systems Managerとは?
AWS Systems Manager is a collection of capabilities
for configuring and managing your Amazon EC2
instances, on-premises servers and virtual machines
(VMs), and certain other AWS resources.
Systems Manager
=
仮想マシンを管理するための機能群
What Is AWS Systems Manager?
https://docs.aws.amazon.com/systems-manager/latest/userguide/what-is-systems-manager.html
8. 8機能一覧
Resource Groups
Insights
• Built-in Insights
• CloudWatch Dashboards
• Inventory Management
• Configuration Compliance
Shared Resources
• Managed Instances
• Activations
• Systems Manager Documents
• Parameter Store
Actions
• Automation
• Run Command
• Session Manager
• Distributor
• Patch Management
• Maintenance Windows
• State Management
• パッチ管理機能
• パッチ管理機能で利用する周辺機能
19. 19Systems Managerの動作要件
Supported Operating Systems
• Windows Server
• Amazon Linux (2012.03 – 2018.03) / Amazon Linux 2 (2.0 and all later versions)
• Ubuntu Server (12.04 LTS, 14.04 LTS, 16.04 LTS, 18.04 LTS)
• Red Hat Enterprise Linux (RHEL) (6.0, 6.5, 6.9, 7.0, 7.4, 7.5, 7.6)
• CentOS (6.0, 6.3 and later 6.x versions, 7.1 and later 7.x versions)
• SUSE Linux Enterprise Server (SLES) (12 and later 12.x versions)
• Raspbian (Jessie, Stretch)
SSM Agent
Interface VPC Endpoint or Internet Access
TLS Certificates
Systems Manager Prerequisites
https://docs.aws.amazon.com/systems-manager/latest/userguide/systems-manager-prereqs.html
20. 20Patch Managerの動作要件
SSM Agent Version
• Version 2.0.834.0 or later of SSM Agent
Supported Operating Systems
• Amazon Linux 2012.03 - 2018.03
• Amazon Linux 2 2 - 2.0
• CentOS 6.5 - 7.6
• Red Hat Enterprise Linux (RHEL) 6.5 - 7.6
• SUSE Linux Enterprise Server (SLES) 12.0 and later 12.x versions
• Ubuntu Server 14.04 LTS, 16.04 LTS, and 18.04 LTS
Patch Manager Prerequisites
https://docs.aws.amazon.com/systems-manager/latest/userguide/patch-manager-prerequisites.html
36. 36
ドキュメントの実行内容も確認可能
About the SSM Document AWS-RunPatchBaseline
https://docs.aws.amazon.com/systems-manager/latest/userguide/patch-manager-about-aws-
runpatchbaseline.html
52. 52CloudWatch Eventsとは?
Amazon CloudWatch Events delivers a near real-time stream of system
events that describe changes in Amazon Web Services (AWS)
resources. Using simple rules that you can quickly set up, you can
match events and route them to one or more target functions or
streams. CloudWatch Events becomes aware of operational changes as
they occur. CloudWatch Events responds to these operational changes
and takes corrective action as necessary, by sending messages to
respond to the environment, activating functions, making changes,
and capturing state information.
What is Amazon CloudWatch Events?
https://docs.aws.amazon.com/AmazonCloudWatch/latest/events/WhatIsCloudWatchEvents.html
AWS Systems Manager Configuration Compliance Events
https://docs.aws.amazon.com/ja_jp/AmazonCloudWatch/latest/events/EventTypes.html#SSM-Configuration-
Compliance-event-types
特定のAWSリソースの変更をトリガーに任意のアクションを実行可能