# Automation using AWS Systems Manger - Run command/Document

Before we jump into the demo, need to understand the key terms

### Systems Manager

AWS Systems Manager allows you to centralize operational data from multiple AWS services and automate tasks across your resources on AWS

### AWS Systems Manager run command

It provides safe, secure remote management of your instances at scale without logging into your servers, replacing the need for bastion hosts, SSH, or remote PowerShell. It provides a simple way of automating common administrative tasks across groups of instances

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719293237380/7bff8c30-9c05-4d09-8021-93c2c4b371eb.webp align="center")

### Step 1: Create an IAM role

* Click on Create Role
    
* select Trusted entity type as "AWS service"
    
* select usecase as "EC2" then click Next
    

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719295077754/88f4490b-b492-4f41-a1e9-52e69f7d60ee.png align="center")

* Under add permissions section , select "[AmazonSSMFullAccess](https://us-east-1.console.aws.amazon.com/iam/home?region=ap-south-1#/policies/details/arn%3Aaws%3Aiam%3A%3Aaws%3Apolicy%2FAmazonSSMFullAccess)" for this demo purpose \[In real time always prefer least-privileged as per the organization standards\] and click next
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719295347921/af38254f-4063-4f8d-a0c8-91c5bdb77850.png align="center")
    
    Give proper name to identify the role then review, and create
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719295779037/7839aabb-7af5-4ca7-bc86-428227fdcd27.png align="center")
    

### Step 2 : Launch EC2 Instance

* Navigate to EC2 service in AWS console and click on Launch an instance
    
* Name = SERVER-1
    
* AMI = Amazon Linux
    
* Instance Type = t2.micro
    
* Key = proceed without key
    
* Security Group = default SG
    
* In advanced details ---&gt; IAM instance profile = <mark>EC2-SSM-DEMO-ROLE</mark> \[Role that we created in step 1\]
    
* Finally click on Launch instance
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719295949466/70054144-bfa5-4937-a760-70b2674f26b2.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719295980986/6a011379-eaa5-4080-a83b-1db5a5ded3e9.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719296015460/afad7ec0-83e4-4d8a-b6f9-98042e8a23f3.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719296055895/2351678c-9933-42ff-b207-25498d17aaa5.png align="center")
    

### Step 3 : Configuring Sessions manager under SSM

* Open systems manager service in AWS console and click on "session manager"
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719296386917/089bca1e-bc50-4f4f-82f2-d46457a4c2c5.png align="center")
    
    hit on "Start session"
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719296425237/f80e3fb9-5f6d-41ed-aea9-a0fc0cf72177.png align="center")
    
    Validate whether we can able to see our Ec2 instance under it or not, if its showing we are **good to proceed** with our demo, else check the SSM agent installation under get **system log of EC2 instance \[Actions--&gt;Monitor and Troubleshoot--&gt;Get system log \]**
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719296481150/4fc0adaf-c820-44f8-91d4-c39cb8d5ddcf.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719296691002/7c64a235-402c-4e43-b3ab-96263ef29e32.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719296717195/3c766144-60a8-4460-b518-e849a9080a11.png align="center")
    

### Step 4 : Executing our script or command under Run command feature of SSM

* click on Run command under SSM ---&gt;Node Management ---&gt; Run command
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719297946576/ba3a8e75-6e68-47f3-a9ea-ddf7971fa0aa.png align="center")
    
    Then click on Run command --&gt; type <mark>AWS-RunShellScript </mark> under command document to execute shell script or cpmmand
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719297986906/4f657d24-68de-489f-ae7b-612ecc52c2ff.png align="center")
    
    Under command parameters paste our shell script \[to install httpd web server\]
    
* ```bash
        #!/bin/bash
        yum install httpd -y
        service httpd start
        chkconfig httpd on
        echo "<h1> This is to Test SSM agent demo lab <h1>" >> /var/www/html/index.html
    ```
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719298097488/5aea0b9b-c35a-4d3f-8b83-ad3f6541dd37.png align="center")
    
    Under Target selection ---&gt; Choose Instances Manually ---&gt; Select our Ec2 instance \[launched in Step2 \]
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719298313517/dfaf5377-ac1f-4761-b6df-b8474b05c988.png align="center")
    
    Output option ---&gt; uncheck Enable an S3 bucket
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719298366984/d4df2a98-0550-4a8a-92ee-f496517446bf.png align="center")
    
* Finally click on Run and see the below output with command status as **Success**
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719298410393/8ad1f003-7f04-4972-bda9-881eec9a8f5b.png align="center")
    

### Step 5 : Grab the EC2 instance public IP and paste it in Brower to access our application

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719298523313/9c188509-4dee-4f81-9678-fbbc973d26b2.png align="center")

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1719298579884/1e738701-7d95-4c06-b255-260a17150927.png align="center")

<mark>Note : Make sure you open port 80 under Ec2 instance Security Group to access the application</mark>

### Clean up

* Terminate Ec2 instance
    
* Delete the IAM role
    

## Conclusion

In this way by using SSM we can able to automate the application deployments in multiple EC2 instances at a time .

#aws #ssm #systemsmanager
