You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

是否存在EC2 Windows实例启动时安装Amazon SSM Agent的引导脚本?

Windows Server 2019 实例SSM Agent自动安装UserData脚本

以下为适用于Windows实例的PowerShell格式引导脚本,会自动完成SSM Agent的下载、静默安装、服务启动配置,可直接添加到实例UserData中:

<powershell>
# SSM Agent安装包下载地址,以下为AWS全球区地址,中国区使用请替换为:https://s3.cn-north-1.amazonaws.com.cn/amazon-ssm/latest/windows/SSMAgentSetup.exe
$ssmInstallerUrl = "https://s3.amazonaws.com/ec2-downloads-windows/SSMAgent/latest/windows_amd64/AmazonSSMAgentSetup.exe"
$tempPath = "C:\SSMInstallTemp"

# 创建临时目录
New-Item -Path $tempPath -ItemType Directory -Force | Out-Null

# 下载安装包
Invoke-WebRequest -Uri $ssmInstallerUrl -OutFile "$tempPath\AmazonSSMAgentSetup.exe" -UseBasicParsing

# 执行静默安装
Start-Process -FilePath "$tempPath\AmazonSSMAgentSetup.exe" -ArgumentList "/quiet" -Wait

# 配置SSM Agent服务为自动启动并立即运行
Set-Service -Name AmazonSSMAgent -StartupType Automatic
Restart-Service -Name AmazonSSMAgent -Force

# 清理临时文件
Remove-Item -Path $tempPath -Recurse -Force -ErrorAction SilentlyContinue
</powershell>

使用及排障说明

  • 实例UserData修改完成后需要重启实例,配置才会正式生效
  • 若配置脚本后仍无法通过Session Manager访问,可依次检查以下配置项:
    • 实例安全组出方向需开放443端口,允许访问SSM相关服务端点,无特殊业务要求建议默认放行所有出方向流量
    • 部署在无公网IP的私有子网中的实例,需要提前在对应VPC中配置SSM服务的VPC端点,保障内网访问链路正常
    • 确认实例挂载的IAM角色已完整附加AmazonSSMManagedInstanceCore权限策略,无自定义权限规则拦截SSM服务调用

内容的提问来源于stack exchange,提问作者Besingi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.04 01:06:05