{"id":28196,"date":"2025-01-29T14:43:27","date_gmt":"2025-01-29T05:43:27","guid":{"rendered":"https:\/\/www.skyarch.net\/blog\/?p=28196"},"modified":"2025-01-29T15:22:24","modified_gmt":"2025-01-29T06:22:24","slug":"aws-systems-manager-fleet-manager%e3%81%ae%e3%83%84%e3%83%bc%e3%83%ab%e3%81%afreadonlyaccess%e6%a8%a9%e9%99%90%e3%81%a7%e3%81%af%e4%bd%bf%e7%94%a8%e3%81%a7%e3%81%8d%e3%81%aa%e3%81%84","status":"publish","type":"post","link":"https:\/\/www.skyarch.net\/blog\/aws-systems-manager-fleet-manager%e3%81%ae%e3%83%84%e3%83%bc%e3%83%ab%e3%81%afreadonlyaccess%e6%a8%a9%e9%99%90%e3%81%a7%e3%81%af%e4%bd%bf%e7%94%a8%e3%81%a7%e3%81%8d%e3%81%aa%e3%81%84\/","title":{"rendered":"AWS Systems Manager Fleet Manager\u306e\u30c4\u30fc\u30eb\u306fReadOnlyAccess\u6a29\u9650\u3067\u306f\u4f7f\u7528\u3067\u304d\u306a\u3044"},"content":{"rendered":"<h2>\u306f\u3058\u3081\u306b<\/h2>\n<p>AWS Systems Manager Fleet Manager\u306e\u30c4\u30fc\u30eb\u306f\u3001\u30de\u30cd\u30b8\u30e1\u30f3\u30c8\u30b3\u30f3\u30bd\u30fc\u30eb\u304b\u3089EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0\u3001\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u30ab\u30a6\u30f3\u30bf\u30fc\u3001\u30d7\u30ed\u30bb\u30b9\u3001\u30e6\u30fc\u30b6\u30fc\u3068\u30b0\u30eb\u30fc\u30d7\u3092\u78ba\u8a8d\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u6a5f\u80fd\u3067\u3059\u3002<br \/>\nReadOnlyAccess\u6a29\u9650\u306e\u307f\u3092\u3082\u3064IAM\u30e6\u30fc\u30b6\u30fc\u3067\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u30ab\u30a6\u30f3\u30bf\u30fc\u3092\u78ba\u8a8d\u3057\u305f\u3068\u3053\u308d\u3001\u30c7\u30fc\u30bf\u3092\u53d6\u5f97\u3067\u304d\u307e\u305b\u3093\u3067\u3057\u305f\u3002<br \/>\n<a href=\"https:\/\/www.skyarch.net\/blog\/wp-content\/uploads\/2025\/01\/b8597e2c3c5a8b5af5bc9c190785a7e9.png\"><img decoding=\"async\" src=\"https:\/\/www.skyarch.net\/blog\/wp-content\/uploads\/2025\/01\/b8597e2c3c5a8b5af5bc9c190785a7e9-1024x455.png\" alt=\"\" \/><\/a><\/p>\n<h2>\u30e6\u30fc\u30b6\u30fc\u30ac\u30a4\u30c9\u3092\u78ba\u8a8d\u3059\u308b<\/h2>\n<p>\u78ba\u8a8d\u3057\u305f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306f<a href=\"https:\/\/docs.aws.amazon.com\/systems-manager\/latest\/userguide\/configuring-fleet-manager-permissions.html\" title=\"\u3053\u3061\u3089\">\u3053\u3061\u3089<\/a>\u3067\u3059\u3002<br \/>\nFleet Manager \u8aad\u307f\u53d6\u308a\u5c02\u7528\u30a2\u30af\u30bb\u30b9\u306e\u30b5\u30f3\u30d7\u30eb\u30dd\u30ea\u30b7\u30fc\u3068ReadOnlyAccess\u30dd\u30ea\u30b7\u30fc\u3092\u6bd4\u8f03\u3057\u305f\u3068\u3053\u308d\u3001ReadOnlyAccess\u30dd\u30ea\u30b7\u30fc\u306b\u306f\u542b\u307e\u308c\u3066\u3044\u306a\u30444\u3064\u306e\u30a2\u30af\u30b7\u30e7\u30f3\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>ssm:SendCommand<br \/>\nssm:StartSession<br \/>\nssm:TerminateSession<br \/>\nkms:GenerateDataKey<\/p>\n<p>ReadOnlyAccess\u306b\u52a0\u3048\u3066\u3053\u308c\u3089\u306e\u66f8\u304d\u8fbc\u307f\u6a29\u9650\u3092\u4ed8\u4e0e\u3059\u308b\u3068\u3001Session Manager\u3084Run Command\u306e\u6a5f\u80fd\u3082\u5229\u7528\u53ef\u80fd\u306b\u306a\u308b\u3053\u3068\u306b\u6ce8\u610f\u304c\u5fc5\u8981\u3067\u3059(\u30b5\u30f3\u30d7\u30eb\u30dd\u30ea\u30b7\u30fc\u306e\u307f\u306e\u5834\u5408\u306f\u8aad\u307f\u53d6\u308a\u6a29\u9650\u4e0d\u8db3\u3068\u306a\u308a\u307e\u3059)\u3002<\/p>\n<p>\u30e6\u30fc\u30b6\u30fc\u30ac\u30a4\u30c9\u3067\u306f\u300c\u8aad\u307f\u53d6\u308a\u5c02\u7528\u30a2\u30af\u30bb\u30b9\u300d\u3068\u3057\u3066\u6848\u5185\u3055\u308c\u3066\u3044\u307e\u3059\u304c\u3001\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u3064\u306a\u3044\u3060\u308a\u30b3\u30de\u30f3\u30c9\u3092\u9001\u3063\u305f\u308a\u3057\u305f\u3044\u3088\u3046\u3067\u3059\u3002<br \/>\n\u6a29\u9650\u3092\u4ed8\u3051\u5916\u3057\u3057\u3066\u7c21\u5358\u306b\u52d5\u4f5c\u78ba\u8a8d\u3057\u305f\u3068\u3053\u308d\u3001\u305d\u308c\u305e\u308c\u4ee5\u4e0b\u306e\u6a5f\u80fd\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u3088\u3046\u3067\u3057\u305f\u3002<\/p>\n<ul>\n<li>Session Manager(ssm:StartSession\u3001ssm:TerminateSession\u3001kms:GenerateDataKey)\n<ul>\n<li>\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u30ab\u30a6\u30f3\u30bf\u30fc<\/li>\n<li>\u30d7\u30ed\u30bb\u30b9<\/li>\n<\/ul>\n<\/li>\n<li>Run Command(ssm:SendCommand)\n<ul>\n<li>\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0<\/li>\n<li>\u30e6\u30fc\u30b6\u30fc\u3068\u30b0\u30eb\u30fc\u30d7<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>SSM Agent\u306e\u30ed\u30b0\u3092\u78ba\u8a8d\u3059\u308b<\/h2>\n<p>SSM Agent\u306e\u30ed\u30b0\u3092\u307f\u306a\u304c\u3089\u3001\u5341\u5206\u306a\u6a29\u9650\u306e\u3042\u308bIAM\u30e6\u30fc\u30b6\u30fc\u3092\u4f7f\u3063\u3066Fleet Manager\u306e\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u30ab\u30a6\u30f3\u30bf\u30fc\u3092\u958b\u3044\u3066\u307f\u307e\u3057\u305f\u3002<br \/>\n\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u30ab\u30a6\u30f3\u30bf\u30fc\u306e\u753b\u9762\u3092\u958b\u3044\u305f\u30bf\u30a4\u30df\u30f3\u30b0\u3067\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u5f35\u3063\u3066\u3044\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3067\u304d\u307e\u3057\u305f\u3002<\/p>\n<pre><code>[root@ip-10-0-0-68 ~]# tail -f \/var\/log\/amazon\/ssm\/amazon-ssm-agent.log\n... \n2025-01-24 09:14:11.1092 INFO [ssm-agent-worker] [MessageService] [MGSInteractor] Processing AgentMessage: MessageType - interactive_shell, Id - xxxxxxxx\n\n2025-01-24 09:14:11.1470 INFO ssm-session-worker - v3.3.987.0\n\n2025-01-24 09:14:11.1093 INFO [ssm-agent-worker] [MessageService] [MGSInteractor] Parsing AgentMessage xxxxxxxx, Payload: {&quot;schemaVersion&quot;: ...}\n\n2025-01-24 09:14:11.1470 INFO picking up runtime config identity selector\n\n2025-01-24 09:14:11.1137 INFO [ssm-agent-worker] [MessageService] [EngineProcessor] document xxxx-xxxx submission started\n\n2025-01-24 09:14:11.1471 INFO Checking if agent identity type OnPrem can be assumed\n\n2025-01-24 09:14:11.1149 INFO [ssm-agent-worker] [MessageService] [EngineProcessor] document xxxx-xxxx submission ended\n\n2025-01-24 09:14:11.1472 INFO Checking if agent identity type EC2 can be assumed\n\n2025-01-24 09:14:11.1911 INFO Agent will take identity from EC2\n\n2025-01-24 09:14:11.1912 INFO [ssm-session-worker] [xxxx-xxxx] Init the cloudwatchlogs publisher\n\n2025-01-24 09:14:11.1912 INFO [ssm-session-worker] [xxxx-xxxx] document: xxxx-xxxx worker started\n\n2025-01-24 09:14:11.1927 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] received plugin config message\n\n2025-01-24 09:14:11.1927 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] {&quot;DocumentInformation&quot;:{&quot;DocumentID&quot;: ...}\n\n2025-01-24 09:14:11.1940 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] Running plugin InteractiveCommands InteractiveCommands\n\n2025-01-24 09:14:11.1959 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Setting up datachannel for session: xxxx-xxxx, requestId: xxxxxxxxxxxx, clientId: \n\n2025-01-24 09:14:11.2623 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Opening websocket connection to: wss:\/\/ssmmessages.ap-northeast-1.amazonaws.com\/v1\/data-channel\/xxxx-xxxx?role=publish_subscribe\n\n2025-01-24 09:14:11.3088 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Successfully opened websocket connection to: 52.119.222.209:443\n\n2025-01-24 09:14:11.3088 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Starting websocket pinger\n\n2025-01-24 09:14:11.3089 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Starting websocket listener\n\n2025-01-24 09:14:11.3093 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Initiating Handshake\n\n2025-01-24 09:14:11.4380 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Client side session manager plugin version is: placeholder_client_ver\n\n2025-01-24 09:14:11.4522 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Verifying encryption challenge..\n\n2025-01-24 09:14:11.4524 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Encryption challenge confirmed.\n\n2025-01-24 09:14:11.4524 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Handshake successfully completed.\n\n2025-01-24 09:14:11.4533 WARN [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Overriding SessionLogsDestination: &quot;none&quot; since logging session data to CloudWatch or S3 is enabled.\n\n2025-01-24 09:14:11.4843 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Starting command executor\n\n2025-01-24 09:14:11.4850 INFO [ssm-session-worker] [xxxx-xxxx] [DataBackend] [pluginName=InteractiveCommands] Plugin InteractiveCommands started<\/code><\/pre>\n<h2>\u304a\u308f\u308a\u306b<\/h2>\n<p>Fleet Manager\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u30ab\u30a6\u30f3\u30bf\u30fc\u306f\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u4f7f\u7528\u72b6\u6cc1\u3092\u8868\u793a\u3059\u308b\u6a5f\u80fd\u306a\u306e\u3067\u3001\u8aad\u307f\u53d6\u308a\u6a29\u9650\u306e\u307f\u3067\u554f\u984c\u306a\u3044\u3068\u8003\u3048\u3066\u3044\u307e\u3057\u305f\u3002\u3057\u304b\u3057\u5b9f\u969b\u306b\u306f\u8868\u793a\u3059\u308b\u3068\u304d\u306b\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u3064\u306a\u3044\u3067\u3044\u308b\u3068\u3044\u3046\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u30de\u30cd\u30b8\u30e1\u30f3\u30c8\u30b3\u30f3\u30bd\u30fc\u30eb\u306e\u88cf\u5074\u306e\u4ed5\u7d44\u307f\u3092\u7406\u89e3\u3059\u308b\u3053\u3068\u306e\u5927\u5207\u3055\u3092\u6539\u3081\u3066\u611f\u3058\u307e\u3057\u305f\u3002<\/p>\n<p><strong>\u53c2\u8003\u30ea\u30f3\u30af<\/strong><\/p>\n<ul>\n<li>Controlling access to Fleet Manager<br \/>\n<a href=\"https:\/\/docs.aws.amazon.com\/systems-manager\/latest\/userguide\/configuring-fleet-manager-permissions.html\">https:\/\/docs.aws.amazon.com\/systems-manager\/latest\/userguide\/configuring-fleet-manager-permissions.html<\/a><\/li>\n<li>ReadOnlyAccess<br \/>\n<a href=\"https:\/\/docs.aws.amazon.com\/aws-managed-policy\/latest\/reference\/ReadOnlyAccess.html\">https:\/\/docs.aws.amazon.com\/aws-managed-policy\/latest\/reference\/ReadOnlyAccess.html<\/a><\/li>\n<li>AWS Systems Manager Agent \u306e\u30ed\u30b0\u8a2d\u5b9a\u3092\u5909\u66f4\u3057\u3066\u307f\u305f<br \/>\n<a href=\"https:\/\/dev.classmethod.jp\/articles\/change-ssm-agent-log-configuration\/\">https:\/\/dev.classmethod.jp\/articles\/change-ssm-agent-log-configuration\/<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u306f\u3058\u3081\u306b AWS Systems Manager Fleet Manager\u306e\u30c4\u30fc\u30eb\u306f\u3001\u30de\u30cd\u30b8\u30e1\u30f3\u30c8\u30b3\u30f3\u30bd\u30fc\u30eb\u304b\u3089EC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0\u3001\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u30ab\u30a6\u30f3\u30bf\u30fc\u3001\u30d7\u30ed\u30bb\u30b9\u3001\u30e6\u30fc\u30b6\u30fc\u3068\u30b0\u30eb\u30fc\u30d7\u3092\u78ba\u8a8d\u3059\u308b\u3053\u3068&#8230;<\/p>\n","protected":false},"author":229,"featured_media":28741,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_locale":"ja","_original_post":"https:\/\/www.skyarch.net\/blog\/?p=28196","footnotes":""},"categories":[830],"tags":[370],"class_list":{"0":"post-28196","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-systems-manager","8":"tag-aws-systems-manager","9":"ja"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/posts\/28196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/users\/229"}],"replies":[{"embeddable":true,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/comments?post=28196"}],"version-history":[{"count":8,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/posts\/28196\/revisions"}],"predecessor-version":[{"id":28215,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/posts\/28196\/revisions\/28215"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/media\/28741"}],"wp:attachment":[{"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/media?parent=28196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/categories?post=28196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/tags?post=28196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}