QuestionQ62

Resilient Cloud Solutions

A DevOps engineer must give several external contractors access to a legacy application running on an Amazon Linux Amazon EC2 instance. The application server is reachable only within a private subnet. The contractors are not permitted to use VPN access.

What should the DevOps engineer do to provide the contractors access to the application server?

Explanation

AWS Systems Manager Session Manager enables IAM-authorized users to start sessions with managed EC2 instances, including instances that do not accept inbound SSH connections. An IAM user with programmatic access, credentials configured for the AWS CLI, and permission for ssm:StartSession can use the Session Manager plugin and aws ssm start-session to access the target instance. SSH keys alone do not create a network path to an instance confined to a private subnet.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!