AWS SSM Patch Manager

0

I have question around AWS SSM Patch manger custom Patch baseline. I create a custom patch baseline for Windows servers and add to Patch group, so far good. I tried to use this custom patch baseline in Maintenance Window task, Couldn't find anything. Only option for Run_Command is AWS-RunPatchBaseline which is default, not the custom that I create.

已提問 3 年前檢視次數 974 次
3 個答案
1

Hello, you are correct -- when you use the document AWS-RunPatchBaseline, you target managed nodes using instance IDs, resource tags, or resource groups. The SSM Agent on each instance makes it's own determination for which baseline it should use based on tags added to itself.

You can either set the baseline as default for the OS or you would want to add Patch Group tags to the instance and the appropriate baseline.

More information can be found in this documentation topic:

https://docs.aws.amazon.com/systems-manager/latest/userguide/sysman-patch-patchgroups.html

AWS
Erik_W
已回答 3 年前
0

Yes I did. Looks like answer is -- When you run AWS-RunPatchBaseline, you can target managed nodes using their ID or tags. SSM Agent and Patch Manager then evaluate which patch baseline to use based on the patch group value that you added to the managed node. If this is true, I am good with this set up.

已回答 3 年前
0
profile picture
專家
已回答 3 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南