{"id":577,"date":"2019-09-19T07:55:38","date_gmt":"2019-09-18T22:55:38","guid":{"rendered":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/blog\/2019\/09\/19\/aws_ssm_ssh"},"modified":"2022-10-28T22:36:18","modified_gmt":"2022-10-28T13:36:18","slug":"aws_ssm_ssh","status":"publish","type":"post","link":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/blog\/2019\/09\/19\/aws_ssm_ssh\/","title":{"rendered":"Session Manager \u4f7f\u3048\u3070\u8e0f\u307f\u53f0\u30b5\u30fc\u30d0\u30fc\u304c\u4e0d\u8981\u306b"},"content":{"rendered":"
2019\u5e747\u6708\u3001 \u30bb\u30c3\u30b7\u30e7\u30f3\u30de\u30cd\u30fc\u30b8\u30e3\u30fc\u304c SSH \u3068 SCP \u306e\u30c8\u30f3\u30cd\u30ea\u30f3\u30b0\u30b5\u30dd\u30fc\u30c8\u3092\u958b\u59cb<\/a><\/p>\n \u4f55\u304c\u5b09\u3057\u3044\u306e\u304b\u3068\u3044\u3046\u3068\u3001\u4e00\u756a\u5927\u304d\u3044\u306e\u306f\u3001<\/p>\n \u8e0f\u307f\u53f0\u30b5\u30fc\u30d0\u30fc\u3092\u4f7f\u7528\u305b\u305a\u306b\u3001 Session Manager \u7d4c\u7531\u3067\u5bfe\u8c61\u306eEC2\u306b\u63a5\u7d9a\u3067\u304d\u308b<\/strong><\/p>\n \u3068\u3044\u3046\u3053\u3068\u3067\u306f\u306a\u3044\u3060\u308d\u3046\u304b\u3002 \u5fc5\u8981\u306a AWS\u30b3\u30f3\u30bd\u30fc\u30eb\u306e <\/p>\n \u3082\u3057\u304f\u306f\u3001 IAM \u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u30ed\u30fc\u30eb\u3092\u78ba\u8a8d\u3057\u3001\u4f5c\u6210\u3059\u308b\u3002 <\/p>\n \u4e0b\u8a18\u306e\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3092\u53c2\u8003\u306b\u3001\u30dd\u30ea\u30b7\u30fc\u3092\u4f5c\u6210\u3001\u4f7f\u7528\u3059\u308bIAM\u30e6\u30fc\u30b6\u30fc\u306b\u4ed8\u4e0e\u3059\u308b\u3002<\/p>\n \u30af\u30a4\u30c3\u30af\u30b9\u30bf\u30fc\u30c8 Session Manager \u306e\u30c7\u30d5\u30a9\u30eb\u30c8 IAM \u30dd\u30ea\u30b7\u30fc - AWS Systems Manager<\/a><\/p>\n (\u30aa\u30d7\u30b7\u30e7\u30f3) AWS CLI \u7528\u306e Session Manager Plugin \u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b \u4e0a\u8a18\u306eURL\u306e\u624b\u9806\u306e\u901a\u308a\u3002<\/p>\n \u3042\u3068\u306f\u901a\u5e38\u306e\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3\u3068\u540c\u3058\u3088\u3046\u306b\u3001SSH\u3092\u3059\u308b\u3060\u3051\u3002 SCP \u3082OK<\/p>\n \u203b \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u306f\u3001\u3054\u89a7\u306e\u901a\u308a\u3001\u30a4\u30f3\u30d0\u30a6\u30f3\u30c9\u306f\u4f55\u3082\u8a31\u53ef\u3057\u3066\u3044\u306a\u3044<\/p>\n <\/p>\n Windows\u306e\u5834\u5408\u306f\u3001 \u30bb\u30c3\u30b7\u30e7\u30f3\u304c\u958b\u59cb\u3055\u308c\u308b\u306e\u3067\u3001\u30ea\u30e2\u30fc\u30c8\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u5074\u306e\u8a2d\u5b9a\u3002 <\/p>\n <\/p>\n \u7121\u4e8b\u63a5\u7d9a\u3067\u304d\u305f\u3002<\/p>\n <\/p>\n 2019\u5e747\u6708\u3001AWS Systems Manager \u30bb\u30c3\u30b7\u30e7\u30f3\u30de\u30cd\u30fc\u30b8\u30e3\u30fc\u3092\u4f7f\u7528\u3057\u3066\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3068\u30b5\u30fc\u30d0\u30fc\u9593\u3067 SSH (Secure Shell) \u304a\u3088\u3073 SCP (Secure Copy) \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30c8\u30f3\u30cd\u30ea\u30f3\u30b0\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u3063\u305f\u3002 \u30bb\u30c3\u30b7\u30e7\u30f3\u30de\u30cd\u30fc\u30b8\u30e3\u30fc\u304c SSH \u3068 SCP \u306e\u30c8\u30f3\u30cd\u30ea\u30f3\u30b0\u30b5\u30dd\u30fc\u30c8\u3092\u958b\u59cb \u4f55\u304c\u5b09\u3057\u3044\u306e\u304b\u3068\u3044\u3046\u3068\u3001\u4e00\u756a\u5927\u304d\u3044\u306e\u306f\u3001 \u8e0f\u307f\u53f0\u30b5\u30fc\u30d0\u30fc\u3092\u4f7f\u7528\u305b\u305a […]<\/p>\n","protected":false},"author":3,"featured_media":684,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[13],"tags":[399],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/577"}],"collection":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/comments?post=577"}],"version-history":[{"count":1,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/577\/revisions"}],"predecessor-version":[{"id":3289,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/577\/revisions\/3289"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/media?parent=577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/categories?post=577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/tags?post=577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}AWS Systems Manager<\/code> \u30bb\u30c3\u30b7\u30e7\u30f3\u30de\u30cd\u30fc\u30b8\u30e3\u30fc\u3092\u4f7f\u7528\u3057\u3066\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3068\u30b5\u30fc\u30d0\u30fc\u9593\u3067
SSH (Secure Shell)<\/code> \u304a\u3088\u3073
SCP (Secure Copy)<\/code> \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30c8\u30f3\u30cd\u30ea\u30f3\u30b0\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u3063\u305f\u3002<\/p>\n
\u5b9f\u969b\u306b\u3084\u3063\u3066\u307f\u305f\u3002<\/p>\n\u524d\u63d0\u6761\u4ef6<\/h2>\n
\n
SSM Agent<\/code> \u306e\u30d0\u30fc\u30b8\u30e7\u30f3
2.3.672.0<\/code> \u4ee5\u4e0a<\/li>\n
ProxyCommand<\/code> \u3092\u30b5\u30dd\u30fc\u30c8\u3059\u308b
SSH<\/code> \u30af\u30e9\u30a4\u30a2\u30f3\u30c8<\/li>\n
AWS CLI<\/code> \u306e\u30d0\u30fc\u30b8\u30e7\u30f3
1.16.12<\/code> \u4ee5\u4e0a<\/li>\n
Session Manager Plugin<\/code> \u306e\u30d0\u30fc\u30b8\u30e7\u30f3
1.1.22.0<\/code> \u4ee5\u4e0a<\/li>\n<\/ul>\n
EC2\u5074\u306e\u8a2d\u5b9a<\/h2>\n
SSM Agent<\/code> \u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u304c 2.3.672.0 \u4ee5\u4e0a<\/strong> \u306a\u306e\u3067\u3001\u305d\u3046\u306a\u3063\u3066\u3044\u306a\u3044\u5834\u5408\u306f\u3001\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3059\u308b\u3002<\/p>\n
SSM Agent\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8<\/h3>\n
AWS Systems Manager<\/code> \u306e
Run Command<\/code> \u304b\u3089 AWS-UpdateSSMAgent<\/strong> \u3092\u5b9f\u884c\u3059\u308b\u3002<\/p>\n
AWS CLI<\/code> \u304b\u3089\u3001\u4e0b\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3002<\/p>\n
aws ssm send-command --document-name "AWS-UpdateSSMAgent" \n --instance-ids <\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9ID> --region ap-northeast-1<\/code><\/pre>\n
EC2\u306b\u30ed\u30fc\u30eb\u4ed8\u4e0e<\/h2>\n
AWS \u7ba1\u7406\u30dd\u30ea\u30b7\u30fc AmazonSSMManagedInstanceCore<\/code> \u3092\u542b\u3093\u3060\u30ed\u30fc\u30eb\u3092\u4ed8\u4e0e\u3059\u308b\u3002<\/p>\n
\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u5074<\/h2>\n
Session Manager \u306e IAM \u30a8\u30f3\u30c9\u30e6\u30fc\u30b6\u30fc\u30dd\u30ea\u30b7\u30fc\u3092\u4f5c\u6210<\/h3>\n
AWS CLI \u306b Session Manager Plugin \u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b<\/h3>\n
\n<\/a><\/p>\n\n
curl "https:\/\/s3.amazonaws.com\/session-manager-downloads\/plugin\/latest\/mac\/sessionmanager-bundle.zip" -o "sessionmanager-bundle.zip"<\/code><\/pre>\n
\n
unzip sessionmanager-bundle.zip<\/code><\/pre>\n
\n
sudo .\/sessionmanager-bundle\/install -i \/usr\/local\/sessionmanagerplugin -b \/usr\/local\/bin\/session-manager-plugin<\/code><\/pre>\n
\n
session-manager-plugin --version\n1.1.31.0<\/code><\/pre>\n
~\/.ssh\/config \u8a2d\u5b9a<\/h3>\n
~\/.ssh\/config<\/code> \u306b\u4e0b\u8a18\u306e\u3088\u3046\u306b\u8a2d\u5b9a\u3059\u308b\u3002<\/p>\n
# SSH over Session Manager\nhost i-* mi-*\n ProxyCommand bash -c "aws ssm start-session --target %h --document-name AWS-StartSSHSession --parameters 'portNumber=%p'"<\/code><\/pre>\n
\u9055\u3046\u306e\u306f\u3001\u30d1\u30d6\u30ea\u30c3\u30afIP\u3067\u306f\u306a\u304f\u3066\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9ID\u3092\u6307\u5b9a\u3059\u308b<\/strong>\u70b9\u3002<\/p>\n$ ssh -i .\/genedev ec2-user@i-0f0963977fbd1a5bb\n\n __| __|_ )\n _| ( \/ Amazon Linux 2 AMI\n ___|\\___|___|\n\nhttps:\/\/aws.amazon.com\/amazon-linux-2\/\n[ec2-user@genedev ~]$<\/code><\/pre>\n
$ scp -i .\/genedev abc.txt ec2-user@i-0f0963977fbd1a5bb:\/tmp\/\nabc.txt 100% 18 0.4KB\/s 00:00<\/code><\/pre>\n
[ec2-user@genedev ~]$ ls -l \/tmp\/abc.txt\n-rw-r--r-- 1 ec2-user ec2-user 18 Sep 16 01:34 \/tmp\/abc.txt\n[ec2-user@genedev ~]$<\/code><\/pre>\n
Windows\u3082\u3084\u3063\u3066\u307f\u305f<\/h2>\n
AWS-StartPortForwardingSession<\/code> \u3092\u4f7f\u7528\u3057\u3066\u3001\u30dd\u30fc\u30c8\u8ee2\u9001\u3092\u884c\u3046\u3002
\u4e0b\u8a18\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3002<\/p>\n$ aws ssm start-session --target i-05bc3e1e3e92f1eed \n --document-name AWS-StartPortForwardingSession \n --parameters '{"portNumber":["3389"], "localPortNumber":["13389"]}'\n\nStarting session with SessionId: eugene_sasaki-0f6e15b8de94ffd19\nPort 13389 opened for sessionId eugene_sasaki-0f6e15b8de94ffd19.<\/code><\/pre>\n
\u3053\u3053\u3067\u306e\u30dd\u30a4\u30f3\u30c8\u306f\u3001 localPortNumber<\/code> \u3067\u6307\u5b9a\u3057\u305f\u30dd\u30fc\u30c813389\u3092\u5165\u308c\u3066\u3001
localhost:13389<\/code> \u3068\u3059\u308b\u3053\u3068\u3002<\/p>\n
\u4eca\u56de\u306e\u30cf\u30de\u30ea\u30dd\u30a4\u30f3\u30c8<\/h2>\n
SSM Agent<\/code> \u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u3057\u3063\u304b\u308a\u3068\u78ba\u8a8d\u3057\u3066\u3044\u306a\u304b\u3063\u305f(
2.3.662.0<\/code> \u3060\u3063\u305f)\u305f\u3081\u3001
\n\u300c\u3064\u306a\u304c\u3089\u306a\u3044\u306a\u30fc\u3002\u4f55\u304c\u60aa\u3044\u3093\u3060\u30fc\u300d\u3063\u3066\u7121\u99c4\u306a\u8abf\u67fb\u6642\u9593\u3092\u8cbb\u3084\u3057\u3066\u3057\u307e\u3063\u305f\u2026\u2026\u3002
\n\u3061\u3083\u3093\u3068\u30d0\u30fc\u30b8\u30e7\u30f3\u306f\u78ba\u8a8d\u3057\u307e\u3057\u3087\u3046\u3002<\/p>\nSSM Agent<\/code> \u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306f\u3001
AWS Systems Manager<\/code> \u306e
Managed Instances<\/code> \u304b\u3089\u78ba\u8a8d\u53ef\u80fd\u3002<\/p>\n
\u518d\u5ea6\u30e1\u30ea\u30c3\u30c8\u3068\u30c7\u30e1\u30ea\u30c3\u30c8\u3092\u304a\u3055\u3089\u3044<\/h2>\n
\u30e1\u30ea\u30c3\u30c8<\/h3>\n
\n
AWS CloudTrail<\/code> \u3067
Session Manager API<\/code> \u306e\u547c\u3073\u51fa\u3057\u3092\u30ed\u30b0\u8a18\u9332\u3067\u304d\u308b<\/li>\n<\/ul>\n
\u30c7\u30e1\u30ea\u30c3\u30c8\uff1f<\/h3>\n
\n
AWS CLI<\/code> \u3092\u4f7f\u3063\u3066\u3001
Session Manager<\/code> \u7d4c\u7531\u3067SSH\u3057\u3066\u3082\u3089\u3046\u3053\u3068\u306b\u306a\u308b\u306e\u3067\u3001\u5c11\u3057\u3060\u3051\u30cf\u30fc\u30c9\u30eb\u9ad8\u3044\u304b\u3082\uff1f\u3057\u308c\u306a\u3044\u3002MMM\u306e\u30e1\u30f3\u30d0\u30fc\u306e\u307f\u304c\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3\u3059\u308b\u3088\u3046\u306a\u74b0\u5883\u306a\u3089\u3001\u554f\u984c\u306a\u3055\u305d\u3046<\/li>\n<\/ul>\n
\u53c2\u8003URL<\/h2>\n
\n