Integrate EC2 Image Builder with SSM Patch Manager baseline

0

How can I integrate EC2 Image Builder receipts to use an existing patches baseline created in Systems Manager Patch Manager? Couldn´t find a native option to do that, so wonder if a script inside the receipt will do the job. Thank you

profile pictureAWS
已提問 4 個月前檢視次數 377 次
1 個回答
2
已接受的答案

You can achieve it through the following:

  • EC2 Image Builder provides two AWS-provided patching components, update-linux and update-windows, which install all pending operating system updates using the UpdateOS action module. These components can be added to your image build pipelines from the list of AWS-provided components. Additionally, you can create custom build components for selective patch installation or updates on supported AMIs using shell scripts or by using the UpdateOS action module​​.
  • In Patch Manager, you can create custom patch baselines and specify various parameters for patch installation and exclusion​​.
  • To link Patch Manager with EC2 Image Builder, you would need to create a maintenance window in Systems Manager. Then, you should register targets (your EC2 instances) to this maintenance window, specifying the patch group key-value tag you created earlier. After this, you assign tasks to the maintenance window, such as patch installation tasks, using the AWS-RunPatchBaselineWithHooks command document. This process allows you to schedule and automate patch installations in alignment with your custom patch baseline​​.

for ref: https://dev.to/aws-builders/building-a-patching-model-using-aws-systems-manager-patch-manager-for-mutable-infrastructure-4739

If this has resolved your issue or was helpful, accepting the answer would be greatly appreciated. Thank you!

profile picture
專家
已回答 4 個月前
profile picture
專家
已審閱 2 個月前
profile pictureAWS
專家
已審閱 4 個月前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南