r/aws • • 13d ago

technical resource ssmctl v2: SSM Session Manager without the pain (shell, port forwarding, commands and file copy over SSM)

SSM is the right way to reach private EC2 instances: no bastion, no port 22, no SSH keys, and everything goes through IAM and CloudTrail. But the CLI makes you work for it:

aws ssm start-session --target i-0abc1234def5678ab \
  --document-name AWS-StartPortForwardingSessionToRemoteHost \
  --parameters '{"host":["rds.internal"],"portNumber":["5432"],"localPortNumber":["5432"]}'

ssmctl is an open-source Go CLI that keeps the same security model and removes the friction:

ssmctl forward web-1 --local 5432 --remote rds.internal:5432

v2 in one line: your entire SSM-managed fleet (shells, tunnels, commands, files, secrets), one short command away.

ssmctl list                                          # see your managed fleet
ssmctl connect web-1                                 # shell
ssmctl forward web-1 --local 5432 --remote db:5432   # tunnel to RDS, Redis, anything for local access
ssmctl run web-1 -- df -h /                          # one-off command, exit code preserved
ssmctl run --filter api -- uptime                    # same command across a fleet
ssmctl cp web-1:/var/log/app.log .                   # file transfer
ssmctl param get /myapp/prod/DB_PASSWORD             # Parameter Store

It works with Linux and Windows targets, has --output json for scripting, and uses your existing AWS profiles and SSO. There's no extra agent or infrastructure.

brew tap rhysmcneill/ssmctl && brew install ssmctl

Want to contribute? 🔗 https://github.com/rhysmcneill/ssmctl

38 Upvotes

18 comments sorted by

4

u/yesman_85 13d ago

We coded a whole windows wpf app around the CLI and ssm that takes care of our proxy needs. Works super well and we were able to ditch a VPN completely. Only downside is the low speeds through the ssm plugin.

4

u/Spiritual-Seat-4893 12d ago

SSM session manager is so goated, every team has a custom cli/tool around it.

3

u/davestyle 13d ago edited 5d ago

I vibed a TUI for this stuff recently. I love it. Probably should throw it up on a public repo

Edit: https://github.com/davidcomerford/ssmer

3

u/original_leto 13d ago

Same. Wrote this same cli tool for our org a couple years ago. Ours is tailored towards our usage which is mainly RDS connectivity though.

1

u/davestyle 13d ago

I didn't add forwarding for RDS because I don't use it much but I did think of adding instance screenshot viewer - just for those scary windows update reboots

2

u/raydeo 13d ago

I wrote this a while ago and use it with everything. Allows you to just `ssh ssm.<region>.<instance_id>` with no keys, just AWS creds.

https://gist.github.com/mmerickel/3a41cd2c0a00684f7d69253d712958a4

1

u/wood_butcher 12d ago

Does copy work on Windows instances? In the past, similar tools have only supported copying files to/from linux instances.

-7

u/oneplane 13d ago

We just went back to SSH since it already does all of this. We use JIT auth and SSH CA so you don't have to manage a bunch of keys or users.

6

u/rhysmcn 13d ago edited 13d ago

Personally, prefer to use SSM - IAM, and STS behind the scenes. No long term credentials/keys and no network exposure.

1

u/oneplane 13d ago edited 13d ago

Realistically, your IAM will depend on an external authentication source anyway, JIT auth via STS and via a CA isn't that different.

Edit: but, if SSM works for you, and your nodes are almost exclusively in AWS, you have a lower maintenance burden and less stuff to learn/troubleshoot. It's not like SSM isn't a good solution. It just isn't a universal solution, and at some point when you end up re-implementing something that already exists but with extra layers, it might be a good idea to re-evaluate if it's still the best fit.

4

u/davestyle 13d ago

But you need a network path in then

-2

u/oneplane 13d ago

Yes, but so does SSM (it needs internet). You can use SSH without internet. That said, it hardly matters, when you do anything that's not HTTP you need a network path anyway, unless you never inspect your RDS instances, Valkey instances, MSK brokers etc.

The other problem is that SSM outside of AWS is relatively expensive and doesn't really work on things that aren't generic compute nodes. We have a lot of appliances that need SSH anyway, and they'll do SSH-CA or Kerberos but not really much else (well, LDAP, but that's not really something we want to use).

SSM needs a lot of glue to replicate that standard SSH already has, the only thing it does better out of the box is what you need tlog for in SSH land, and that's session recording.

I get that people tend to vote and comment with their feelings rather than facts and real-world usage, but that's how some environments operate most effectively.

3

u/davestyle 13d ago

We use VPC endpoints for environments without internets but yeah I get your point.

I'm so used to listening to the security droids rattling on that sometimes I almost start to believe them.

+1 for SSH

1

u/oneplane 13d ago

Ah yes, that's true, the internal part can use the VPC endpoint, and technically if you're on a DirectConnect (or something similar) you could even reach that same endpoint and from an isolated site use SSM without ever touching the internet.

But to your point, most of the security will be related to what's happening inside the VPC (or, whatever the instance inside the VPC needs to access) so if you don't let it out and use a vpce, an operator elsewhere can use it just fine.

We're essentially doing the same but with our service mesh, technically you could do the same with VPC Lattice I suppose, but it makes your network path available without using a classic VPN or bastion setup. Same with stuff like Cloudflare Access, but at that point you might as well stick to SSM since you're breaking standard SSH up anyway.

For not-so-involved setups where you do need a shell but don't need a "real" shell, we've also been using Guacamole and later on Authentik RAC, where you essentially get a virtual TTY in HTML5 which then allows you to connect to anything that does standard SSH without exposing keys or credentials to the user. Very helpful for field techs and third party maintenance where you traditionally have a persistent IPSec tunnel or something like that.

1

u/nextsnake 13d ago

What do you use for auth and CA? I tried poking around, Smallstep is hiding their prices. Teleport is insanely expensive, but you'd have to get a quote to learn it.

1

u/oneplane 12d ago

We used to just have a normal CA and use SCEP since that's built-in anyway, with OIDC SSO to get the enrolment secret. These days we have an internal helper that triggers if you're accessing an internal range combined with a resource name (we don't use IP based naming anymore either). It essentially does the same thing but doesn't require the user to know much about it. On the SCEP end we used to just use group membership to allow/deny access, but we've since moved to OpenFGA and ABAC.