The Amazon EC2 service has a hidden gem: a feature that enables a developer to remotely run commands and scripts...
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
on one or more servers. Not only does it work for EC2 instances, but it also automates commands on local servers.
The EC2 Run Command feature is a powerful automation tool for the AWS platform. So, it's important to know how to use it to create consistency across cloud-based and on-premises workloads.
To get started, install an agent on Elastic Compute Cloud (EC2) instances or on-premises servers. Next, run predefined or custom-built commands and scripts on servers to install software, update OS configuration, perform diagnostics or gather configuration information. Execute commands on multiple servers from a single location in the AWS Management Console; this also displays the success or failure of command outputs.
It's not hard to combine the EC2 Run Command feature with existing workloads. Follow these steps to install an application on an existing instance running on AWS.
Configure an IAM Role
EC2 Run Command is part of the EC2 Simple Systems Manager (SSM) suite of tools and services. Grant EC2 instances permission to call the SSM API to process commands and scripts invoked from the EC2 console. Create an AWS Identity and Access Management (IAM) role with required permissions, and assign that role to the instances. To do this, follow these steps:
- From the AWS console home screen, click on the IAM shortcut under Security, Identity, and Compliance to navigate to the IAM console.
- In the IAM console, click on Roles.
- Click on the Create new role button.
- Under Select role type, click on Amazon EC2.
- On the Attach Policy screen, select the AmazonEC2RoleforSSM policy and then click Next Step.
- On the final screen, give the role a name, such as SSMRole, and click Create role.
Install the SSM Agent
After you created the IAM role, install the SSM agent. When creating new EC2 instances, associate the IAM role established in the last step with the instance. Configure the instance to run a user data script and install the SSM agent when the server boots up.
In this example, I'll launch a new instance in the console using the Amazon Linux machine image.
Under Advanced Details, configure a user data script to download and install the SSM agent during instance launch, as shown in Figure 2. AWS offers several versions of the SSM agent to match different OS needs.
Send a command in the EC2 console
After deploying the instance, commands can execute remotely from the EC2 console. Scroll down on the bottom left-hand side of the console, and click on the Run Command button within System Manager Services.
The system will prompt you to select a command document. There are several built-in command documents that perform common tasks, such as configure Docker on a Linux instance or join a Windows instance to an Active Directory domain. In this example, let's run a custom script called AWS-RunShellScript.
Finally, select the instance to run the script against. Select EC2 instances that have the SSM agent running and have the IAM permissions to communicate with the SSM API (Figure 3). It's possible to select multiple instances on this screen to run commands in parallel against a fleet of servers at once.
After selecting the instance, scroll down to the Commands field, and input a single command or multiline script. In this example, I'll use the Yellowdog Updater, Modified (yum) package manager to install an Apache web server, as shown in Figure 4.
Finally, click on the Run button at the bottom of the screen. After executing the command, you can view the progress in real time in the EC2 Run Command console. Select View Output to see any output a command returns.
Automate all the things with the AWS PowerShell module
The market demanded more hybrid tools -- and AWS responded
AWS and Chef tools tie together to automate workloads