SSM Patch Manager Configure Patch Sources for Managed Instances

0

hello, how to specify patching source for Windows and Linux (RHEL, Amazon Linux2, Ubuntu etc.) instances without granting internet access to these instances? My search results are not returning public repositories for patches for said OS but let's say I have a public repo for patches, https://epel.mirror.digitalpacific.com.au/7/

  1. Do I specify the link in Patch Baseline for managed instance?
  2. What options does the managed instance have to reach to this repository?
  3. Is WSUS in public subnet the only approach for patching Windows instances?
질문됨 7달 전308회 조회
1개 답변
1
수락된 답변

Hello.

  1. Do I specify the link in Patch Baseline for managed instance?

The repository URL is required when creating a custom patch baseline as shown in the document below.
https://docs.aws.amazon.com/systems-manager/latest/userguide/patch-manager-create-a-patch-baseline-for-linux.html

  1. What options does the managed instance have to reach to this repository?

A NAT Gateway is required to use public repositories such as the EPEL repository.

  1. Is WSUS in public subnet the only approach for patching Windows instances?

You can update without using WSUS by creating a NAT Gateway and accessing the Microsoft Update Catalog in the same way as the EPEL repository.

profile picture
전문가
답변함 7달 전
profile picture
전문가
검토됨 한 달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인