Networking
Part 4 of 6 · Private NetworkingSecure Access Without SSH — AWS SSM Session Manager, Bastions & Alternatives
Session Manager gives a shell and supported port forwarding without inbound SSH or a public IP. The agent dials Systems Manager outbound. IAM authorizes the operator. A private subnet still needs NAT or interface endpoints, and logging is not automatic.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
Default admin path on AWS
Prefer
SSM with least privilege, private connectivity, and logging
No inbound management port. IAM starts the session. The agent already holds an outbound channel. Configure S3 or CloudWatch logging on purpose.
- Shell I/O can be logged when preferences and permissions exist.
- Port-forwarded bytes are not a transcript.
- Remove TCP 22 after the new path is proven.
Alternative
Public SSH or a shared bastion
Easy to stand up. Scanners find port 22. A bastion reduces entry points and still needs keys, patches, and a story for lateral movement.
- EC2 Instance Connect shortens key lifetime and still needs SSH reachability.
- EIC Endpoint is a managed path to SSH, not a replacement for SSH.
- Mixed-cloud fleets may want IAP, Cloudflare Access, or Tailscale instead.
Overview
Administrative access is part of the attack surface. Opening TCP 22 to the internet invites scanning. SSH only from a bastion still leaves an inbound service, a host, and a credential path. Shared keys make "who did what" hard.
Session Manager provides interactive shells and supported port forwarding without an inbound SSH rule or a public IP. The agent on the instance initiates outbound HTTPS to Systems Manager. An authorized operator starts a session through the AWS API, using IAM rather than an SSH key.
This is not "no network required." The instance must reach Systems Manager through NAT or VPC interface endpoints. The operator needs IAM and a compatible CLI or session-manager plugin. Logging must be configured. Shell transcripts and port-forward visibility are different.
Prefer SSM for AWS-native fleets when connectivity and features fit. Choose a bastion or another product only for a requirement you can name.
Access models
- Public SSH. Easy, continuously scanned. Keys must be issued, rotated, and removed. Records are often incomplete.
- Bastion. Fewer SSH entry points. Still inbound SSH, patching, keys, and a lateral-movement foothold if it is compromised.
- SSM Session Manager. No inbound management port. IAM authorizes sessions. Metadata and, if configured, shell I/O can go to CloudWatch Logs or S3. Run Command and inventory are related features.
- EC2 Instance Connect. Pushes a short-lived SSH public key. The instance still needs a reachable SSH path.
- EC2 Instance Connect Endpoint. A managed network path for SSH to private instances. You can avoid a public IP. SSH and its controls remain.
- Zero-trust access (IAP, Cloudflare Access, Tailscale). Identity-aware access across environments. You take on that control plane, agents, and policy. Compare identity, audit, reachability, and who operates it — not only whether port 22 is hidden.
Session path
The operator calls the Systems Manager API. Systems Manager checks authorization and brokers the session to the agent, which already maintains outbound connections. The agent opens a shell or a supported forward.
Sequence
- 1
Engineer
Step 1 AuthZ
- 2
Engineer → SSM API
StartSession
- 3
SSM API → SSM Agent
Outbound HTTPS
- 4
SSM Agent → Shell
PTY or local port
- 5
Engineer
Optional log to S3
Lesson map
Secure Access Without SSH — AWS SSM Session Manager, Bastions & Alternatives
Session Manager gives a shell and supported port forwarding without inbound SSH or a public IP. The agent dials Systems Manager outbound. IAM authorizes the operator. A private subnet still needs NAT or interface endpoints, and logging is not automatic.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB eng["Engineer"] api["SSM API"] agent["SSM Agent"] shell["Shell"] eng -->|StartSession| api api -->|Outbound HTTPS| agent agent -->|PTY or local| shell
In a private subnet, provide outbound access with NAT or interface endpoints, commonly ssm and ssmmessages. Needs vary by region, agent version, and feature. Check current guidance for ec2messages and other dependencies. Allow TCP 443, and fix DNS and endpoint security groups.
Configure session preferences and the S3 or CloudWatch permissions, encryption, retention, and access. Port-forwarding sessions do not transcript the forwarded application traffic. Treat them as access paths, not as database audit.
From bastion to target state
A bastion concentrates risk. A stolen key or a CVE is a foothold into the private fleet. Removing the box is not enough: identity policy, endpoint reachability, instance permissions, and monitoring still have to be correct. Keep a documented break-glass route that is protected, tested, and audited. Do not leave a permanent broad SSH exception.
Flow
- 1
1 Users with SSH keys
- next2 Bastion port 22
- 2
2 Bastion port 22
- next3 Private fleet
- 3
3 Private fleet
- 4
4 Stolen key or CVE
- next5 Lateral movement
- 5
5 Lateral movement
- next6 Fleet probed
- 6
6 Fleet probed
- 7
7 Users via IAM
- next8 Session Manager
- 8
8 Session Manager
- next9 Fleet without port 22
- 9
9 Fleet without port 22
Sandbox: pick an access pattern (Python)
Teaching aid. Production also checks OS support, compliance, user identity, and whether the session type exists. Mixed cloud wins first in this sketch, then compliance logging, then TCP forward.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Forwarding a local port does not record the application data. Confirm the target is a managed node.
Sandbox: tag-scoped StartSession (TypeScript)
Illustrates intent. It is not a deployable policy. Real policies need the session document, resource ARN, related actions, and condition-key behavior. A tag condition is not a boundary if untrusted principals can retag the instance.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Also restrict tag mutation. Users may need end or resume permissions. Session documents change what a session can do. Avoid ssm:*.
Checklist
- Identity. Dedicated roles. Scope instances, environments, and session documents.
- Instance role. Instance profile for the agent.
AmazonSSMManagedInstanceCoreis a common start. Review it against least privilege. - Agent and path. Agent installed and current. TCP 443 to the right endpoints via NAT or interface endpoints. DNS and endpoint policy included.
- Exposure. Remove inbound TCP 22. Check security groups, NACLs, and host firewalls.
- Logging. Preferences, encryption, retention, access, and an alert. Test what port forwarding does not record.
- Operations. Who may touch production, how sessions end, and how break-glass works. Review CloudTrail.
- Port forwarding. Fine for a private database or RDP admin flow. Destination authz still applies. A tunnel is not application control.
GCP and Azure
GCP IAP TCP forwarding plus OS Login is the usual identity-controlled SSH story. Firewall for the IAP range, not the internet, and review audit logs.
Azure Bastion offers browser or native access without public management ports. JIT VM access opens an NSG for a limited time and still relies on a network path. Azure Arc can manage machines outside Azure. Pick the mechanism from where the machine runs.
These products share a goal. They are not the same control.
Pitfalls
List the interface endpoints you would add for Session Manager in one region. Then write the IAM condition that limits prod sessions, and the one log you would open after a port-forward to a database. Say what that log does not contain.
Interview Q&A
Does an instance need a public IP for Session Manager?
Answer
No. The agent needs outbound connectivity to Systems Manager through NAT or suitable interface endpoints. A private subnet with neither path will not register.
How does Session Manager compare with a bastion?
Answer
A bastion accepts inbound connections and must be patched and protected from credential theft and lateral movement. SSM uses IAM and an agent-initiated outbound channel, so inbound SSH can often be removed. You still need IAM, endpoints, and monitoring.
How would you restrict production sessions?
Answer
A dedicated role, narrowly scoped StartSession, conditions on instance tags and session documents, and a block on unauthorized tag changes. Add approval or just-in-time workflow where required. Log sessions. Test allow and deny. Keep a tested break-glass process. One condition key is not the only control.
What is the difference between EIC Endpoint and SSM?
Answer
An EC2 Instance Connect Endpoint is a network path for SSH to private instances. SSH remains the protocol. SSM is an IAM-authorized session through the agent, and it can include Run Command and inventory. Choose from protocol needs and audit expectations.
Does SSM log everything typed or tunneled?
Answer
Not automatically. Session logging must be configured. Shell I/O has prerequisites and limits. Port-forwarded application traffic is not a shell transcript. Use database or application audit for actions through a tunnel.
Why is an instance not a managed node?
Answer
Stopped or old agent, missing instance profile, blocked outbound HTTPS, missing endpoints, DNS or endpoint-policy errors, or an unsupported setup. Check agent logs, IAM, routes, security groups, and endpoint reachability in that order.
Who needs permission, the user or the instance?
Answer
Both, for different jobs. The user needs StartSession on the target. The instance profile lets the agent talk to Systems Manager. One without the other fails closed in a confusing way.
When would you not choose SSM?
Answer
Mixed clouds, a protocol SSM does not session, or a compliance tool that already owns workforce access. Then compare IAP, Cloudflare Access, or a VPN with an IdP. Depth for tunnels is the next lesson.
What is a safe break-glass story?
Answer
A documented, time-limited, alarmed path. Not a standing 0.0.0.0/0 rule on port 22 that everyone calls temporary.
Which endpoints do people forget?
Answer
ssm and ssmmessages are the common pair. Confirm ec2messages and any feature-specific endpoint for your region and agent. Private DNS has to win or the agent still tries the public name.
Is AmazonSSMManagedInstanceCore automatically least privilege?
Answer
It is a common starting point. Review the permissions against what that fleet actually needs. Least privilege is the review, not the managed-policy name.
How does port forwarding interact with a private database?
Answer
It can reach the database without a public address. It does not authenticate the SQL session or record the queries. Keep database authz and audit.