4 ms·
If you just want to enable ssh to ec2 instances (through SSM) using ssh i-… you can add the following lines to your ssh config https://gist.github.com/nicornk/
by nicornk 2y ago
If you just want to enable ssh to ec2 instances (through SSM) using ssh i-… you can add the following lines to your ssh config
https://gist.github.com/nicornk/5d2c0cd02179f9b46cc7df459af0c16c https://gist.github.com/nicornk/5d2c0cd02179f9b46cc7df459af0...
host i-*
IdentityFile ~/.ssh/id_rsa
TCPKeepAlive yes
ServerAliveInterval 120
User ec2-user
ProxyCommand sh -c "aws ec2 start-instances --instance-ids %h ; aws ec2 wait instance-running --instance-ids %h ; aws ec2-instance-connect send-ssh-public-key --instance-id %h --instance-os-user %r --ssh-public-key 'file://~/.ssh/id_rsa.pub' --availability-zone $(aws ec2 describe-instances --instance-ids %h --query 'Reservations[0].Instances[0].Placement.AvailabilityZone') ; aws ssm start-session --target %h --document-name AWS-StartSSHSession --parameters 'portNumber=%p'"
This will also allow VSCode remote development.
- deleted 2y ago[deleted]
- Galanwe 2y agoMy variation is to use a custom script as `ProxyCommand` that resolves private route53 DNS names to instance ids, because remembering instance IDs is insane.
- smackeyacky 2y agoMine is to run a Tailscale node on a tiny ec2 instance. Not only enabling ssh but direct access to database instances, s3 buckets that are blocked from public access etc
- scarface_74 2y agoHow are S3 buckets blocked from public access? I mean I know there is literally a “Block public access” feature that keeps S3 buckets from being read or written by unauthenticated users. But as far as I know without some really weird bucket ACLs you can still access S3 buckets if you have the IAM credentials. Before anyone well actually’s me. Yes I know you can also route S3 via AWS internal network with VPC Endpoints between AWS services.
- Galanwe 2y agoYou essentially add a policy that limits the access to only come from your VPC endpoint.
- nijave 2y agoIn general, condition keys https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_p... And https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazons3.html#amazons3-policy-keys https://docs.aws.amazon.com/service-authorization/latest/ref... Specifically the vpce one as the other poster mentioned but there's other like IP limits Another way is an IdP that supports network or device rules. For instance, Cloudflare Access and Okta you can add policies where they'll only let you auth if you meet device or network requirements which achieved the same thing
- Galanwe 2y ago> Specifically the vpce one as the other poster mentioned but there's other like IP limits IPs don't cut it to prevent public access. I can create my own personal AWS account, with the private IP I want, and use the credentials from there. There's really just VPC endpoints AFAIK.
- icedchai 2y agoI run an EC2 instance with SSM enabled. I then use the AWS CLI to port forward into the 'private' database instance or whatever from my desktop. The nice thing about this is it's all native AWS stuff, no need for 3rd party packages, etc.