Integrate EC2 Image Builder with SSM Patch Manager baseline

0

How can I integrate EC2 Image Builder receipts to use an existing patches baseline created in Systems Manager Patch Manager? Couldn´t find a native option to do that, so wonder if a script inside the receipt will do the job. Thank you

1개 답변
2
수락된 답변

You can achieve it through the following:

  • EC2 Image Builder provides two AWS-provided patching components, update-linux and update-windows, which install all pending operating system updates using the UpdateOS action module. These components can be added to your image build pipelines from the list of AWS-provided components. Additionally, you can create custom build components for selective patch installation or updates on supported AMIs using shell scripts or by using the UpdateOS action module​​.
  • In Patch Manager, you can create custom patch baselines and specify various parameters for patch installation and exclusion​​.
  • To link Patch Manager with EC2 Image Builder, you would need to create a maintenance window in Systems Manager. Then, you should register targets (your EC2 instances) to this maintenance window, specifying the patch group key-value tag you created earlier. After this, you assign tasks to the maintenance window, such as patch installation tasks, using the AWS-RunPatchBaselineWithHooks command document. This process allows you to schedule and automate patch installations in alignment with your custom patch baseline​​.

for ref: https://dev.to/aws-builders/building-a-patching-model-using-aws-systems-manager-patch-manager-for-mutable-infrastructure-4739

If this has resolved your issue or was helpful, accepting the answer would be greatly appreciated. Thank you!

profile picture
전문가
답변함 4달 전
profile picture
전문가
검토됨 2달 전
profile pictureAWS
전문가
검토됨 4달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠