3 ms·
I'm honestly a little disappointed here, I feel like there is not fully baked but it is so close. Unlike SSM, Instance connect goes direct over SSH - so you ei
by different_sort 7y ago
I'm honestly a little disappointed here, I feel like there is not fully baked but it is so close.
Unlike SSM, Instance connect goes direct over SSH - so you either need to be inside of your AWS network, on a bastion host that can route to your AWS network, or use a public IP address.
It would be great if they combined this functionality with the HTTP wrapping capability so that I do not need to expose SSH/route to SSH ports in any way but can also use IAM policy to control which unix user a given IAM principal can land in the host as (Example use case would be I would only want a certain class of user to land as a user with sudo/root access).
This is still valuable to my use case, and we'll go ahead with it using the bastion approach most likely until they hopefully integrate this with their HTTP SSH wrapper.