Creating an IAM Role and Configuring an EC2 Instance for AWS Systems Manager

30 minutes
  • 3 Learning Objectives

About this Hands-on Lab

In this hands-on lab, you will learn about the IAM role necessary for configuring an EC2 instance with the AWS Systems Manager service. We’ll create and attach a role to an EC2 instance via the AWS Management Console (GUI) and confirm that it is configured with the SSM service by checking in the Systems Manager console as a managed instance.

Learning Objectives

Successfully complete this lab by achieving the following learning objectives:

Create an EC2 IAM Role with the Systems Manager Policy for EC2
  1. Access the IAM console, and create a role.
  2. Attach the AmazonEC2RoleforSSM policy to the role during creation.
  3. Name your role MySSMRole.

Note: When working via the GUI, AWS auto-creates an IAM instance profile when you create a role for EC2; whereas, when working in the CLI, one has to create and attach an IAM instance profile to the IAM role themselves.

Launch an EC2 Instance
  1. Once you’re on the AMI selection screen, select the latest Amazon Linux 2 AMI (it has the SSM Agent installed).
  2. On the Configure Instance Details page, select the IAM role you created earlier. Leave all other configuration details of the instance at their default.
  3. Select an existing security group for this instance — it should already be created and named SG.
  4. Add a tag key called Name, with a value of MySSMInstance. You can tag it with whatever value you prefer. You’ll be using the instance tag to identify that SSM can see and communicate with the instance later on.
  5. You don’t need to generate a key pair for this EC2 instance since you won’t be logging in to it, so you can click Proceed without a keypair, and launch the instance.
Verify the EC2 Instance Is Properly Configured with Systems Manager

Navigate to Systems Manager > Fleet Manager to view the EC2 instance.

Additional Resources

Log in to the live AWS environment using the credentials provided. Make sure you're in the N. Virginia (us-east-1) Region throughout the lab.

A subnet (SubnetA) and security group (SG) have already been provisioned as part of this lab to use when running/creating the EC2 instance.

Note: After creating the EC2 instance, you won't find Managed instances under Instances and Nodes. You'll see the EC2 instance under Fleet Manager.

What are Hands-on Labs

Hands-on Labs are real environments created by industry experts to help you learn. These environments help you gain knowledge and experience, practice without compromising your system, test without risk, destroy without fear, and let you learn from your mistakes. Hands-on Labs: practice your skills before delivering in the real world.

Sign In
Welcome Back!

Psst…this one if you’ve been moved to ACG!

Get Started
Who’s going to be learning?