This repository demonstrates how to use Ansible with AWS Systems Manager (SSM) to securely manage EC2 instances across multiple AWS accounts without SSH.
# Enable and install Ansible
sudo amazon-linux-extras enable ansible2
sudo yum install -y ansible
# Verify Ansible
ansible --version
# Install AWS SSM Session Manager plugin
sudo yum install -y https://s3.amazonaws.com/session-manager-downloads/plugin/latest/linux_64bit/session-manager-plugin.rpm
# Check if AWS Ansible collection is installed
ansible-galaxy collection list
# Install Python dependencies
sudo yum install -y python3-pip
pip install boto3 botocore
- S3 Bucket
Create an S3 bucket to store artifacts used by the SSM connection plugin. Add a resource-based policy to allow access from the Ansible role in member accounts:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::xxxx:role/Ansible-member-role"
},
"Action": [
"s3:GetBucketLocation",
"s3:ListBucket",
"s3:GetObject",
"s3:PutObject"
],
"Resource": [
"arn:aws:s3:::ansible-ssm-bucket",
"arn:aws:s3:::ansible-ssm-bucket/*"
]
}
]
}
This role should be attached to the Ansible Master Node EC2 instance.
Policies required:
AmazonSSMManagedInstanceCore- Assume Role →
Ansible-member-rolein all target AWS accounts - S3 permissions →
s3:GetObject
This role is trusted by the Ansible-control-role.
Permissions granted (EC2 + SSM + S3):
-
EC2:
ec2:DescribeInstancesec2:DescribeTagsec2:DescribeRegions
-
SSM:
ssm:SendCommandssm:StartSessionssm:DescribeInstanceInformation
-
S3:
s3:GetObjects3:PutObject
# List inventory
ansible-inventory -i acc1_aws_ec2.yml --list
# (Note: file extension MUST be .yml, otherwise it won’t work)
# Assume cross-account role
CREDS=$(aws sts assume-role \
--role-arn arn:aws:iam::xxxx:role/Ansible-member-role \
--role-session-name AnsibleSSM)
export AWS_ACCESS_KEY_ID=$(echo $CREDS | jq -r '.Credentials.AccessKeyId')
export AWS_SECRET_ACCESS_KEY=$(echo $CREDS | jq -r '.Credentials.SecretAccessKey')
export AWS_SESSION_TOKEN=$(echo $CREDS | jq -r '.Credentials.SessionToken')
export AWS_DEFAULT_REGION=us-east-1
## ✅ Test Cross-Account Role Setup
```bash
# Verify role assumption
aws sts assume-role \
--role-arn arn:aws:iam::629843008849:role/Ansible-member-role \
--role-session-name "AnsibleSSM"
# Test SSM connection to EC2 instance
aws ssm start-session --target i-fdfdf --region us-east-1