aws-ssm
Version
5.0.0
contains end to end support for the resourceDocument
. However resources likeMaintenance Window
andAssociation
which will provide all the functionalities for commercial regions , might experience limitations for handling real time events only in gov cloud regions.Version
5.0.2
contains end to end support for the resourceDocument
,Maintenance Window
andAssociation
Recommended Version
Version
5.14.0
Released On
Jan 05, 2023
Depends On
Resource Types
- AWS > SSM
- AWS > SSM > Association
- AWS > SSM > Document
- AWS > SSM > Maintenance Window
- AWS > SSM > Managed Instance
- AWS > SSM > Parameter
Control Types
- AWS > SSM > Association > Active
- AWS > SSM > Association > Approved
- AWS > SSM > Association > CMDB
- AWS > SSM > Association > Configured
- AWS > SSM > Association > Discovery
- AWS > SSM > Association > Usage
- AWS > SSM > Document > Active
- AWS > SSM > Document > Approved
- AWS > SSM > Document > CMDB
- AWS > SSM > Document > Configured
- AWS > SSM > Document > Discovery
- AWS > SSM > Document > Tags
- AWS > SSM > Document > Usage
- AWS > SSM > Inventory Management
- AWS > SSM > Maintenance Window > Active
- AWS > SSM > Maintenance Window > Approved
- AWS > SSM > Maintenance Window > CMDB
- AWS > SSM > Maintenance Window > Configured
- AWS > SSM > Maintenance Window > Discovery
- AWS > SSM > Maintenance Window > Tags
- AWS > SSM > Maintenance Window > Usage
- AWS > SSM > Managed Instance > CMDB
- AWS > SSM > Managed Instance > Discovery
- AWS > SSM > Parameter > Active
- AWS > SSM > Parameter > Approved
- AWS > SSM > Parameter > CMDB
- AWS > SSM > Parameter > Discovery
- AWS > SSM > Parameter > Encryption at Rest
- AWS > SSM > Parameter > Tags
- AWS > SSM > Parameter > Usage
- AWS > SSM > Stack
Policy Types
- AWS > SSM > API Enabled
- AWS > SSM > Approved Regions [Default]
- AWS > SSM > Association > Active
- AWS > SSM > Association > Active > Age
- AWS > SSM > Association > Active > Last Modified
- AWS > SSM > Association > Approved
- AWS > SSM > Association > Approved > Custom
- AWS > SSM > Association > Approved > Regions
- AWS > SSM > Association > Approved > Usage
- AWS > SSM > Association > CMDB
- AWS > SSM > Association > Configured
- AWS > SSM > Association > Configured > Claim Precedence
- AWS > SSM > Association > Configured > Source
- AWS > SSM > Association > Regions
- AWS > SSM > Association > Usage
- AWS > SSM > Association > Usage > Limit
- AWS > SSM > CMDB
- AWS > SSM > Document > Active
- AWS > SSM > Document > Active > Age
- AWS > SSM > Document > Active > Last Modified
- AWS > SSM > Document > Approved
- AWS > SSM > Document > Approved > Custom
- AWS > SSM > Document > Approved > Regions
- AWS > SSM > Document > Approved > Usage
- AWS > SSM > Document > CMDB
- AWS > SSM > Document > Configured
- AWS > SSM > Document > Configured > Claim Precedence
- AWS > SSM > Document > Configured > Source
- AWS > SSM > Document > Regions
- AWS > SSM > Document > Tags
- AWS > SSM > Document > Tags > Template
- AWS > SSM > Document > Usage
- AWS > SSM > Document > Usage > Limit
- AWS > SSM > Enabled
- AWS > SSM > Inventory Management
- AWS > SSM > Inventory Management > Inventory Association
- AWS > SSM > Inventory Management > Inventory Association > Name
- AWS > SSM > Inventory Management > Inventory Association > Name Prefix
- AWS > SSM > Inventory Management > Inventory Association > Parameters
- AWS > SSM > Inventory Management > Inventory Association > Schedule
- AWS > SSM > Inventory Management > Inventory Association > Source
- AWS > SSM > Inventory Management > Inventory Association > Targets Tag Key
- AWS > SSM > Inventory Management > Inventory Association > Targets Tag Value
- AWS > SSM > Maintenance Window > Active
- AWS > SSM > Maintenance Window > Active > Age
- AWS > SSM > Maintenance Window > Active > Last Modified
- AWS > SSM > Maintenance Window > Approved
- AWS > SSM > Maintenance Window > Approved > Custom
- AWS > SSM > Maintenance Window > Approved > Regions
- AWS > SSM > Maintenance Window > Approved > Usage
- AWS > SSM > Maintenance Window > CMDB
- AWS > SSM > Maintenance Window > Configured
- AWS > SSM > Maintenance Window > Configured > Claim Precedence
- AWS > SSM > Maintenance Window > Configured > Source
- AWS > SSM > Maintenance Window > Regions
- AWS > SSM > Maintenance Window > Tags
- AWS > SSM > Maintenance Window > Tags > Template
- AWS > SSM > Maintenance Window > Usage
- AWS > SSM > Maintenance Window > Usage > Limit
- AWS > SSM > Managed Instance > CMDB
- AWS > SSM > Managed Instance > Regions
- AWS > SSM > Parameter > Active
- AWS > SSM > Parameter > Active > Age
- AWS > SSM > Parameter > Active > Budget
- AWS > SSM > Parameter > Active > Last Modified
- AWS > SSM > Parameter > Approved
- AWS > SSM > Parameter > Approved > Budget
- AWS > SSM > Parameter > Approved > Custom
- AWS > SSM > Parameter > Approved > Parameter Type
- AWS > SSM > Parameter > Approved > Regions
- AWS > SSM > Parameter > Approved > Usage
- AWS > SSM > Parameter > CMDB
- AWS > SSM > Parameter > CMDB > Included Parameter Value Types
- AWS > SSM > Parameter > Encryption at Rest
- AWS > SSM > Parameter > Encryption at Rest > Customer Managed Key
- AWS > SSM > Parameter > Regions
- AWS > SSM > Parameter > Tags
- AWS > SSM > Parameter > Tags > Template
- AWS > SSM > Parameter > Usage
- AWS > SSM > Parameter > Usage > Limit
- AWS > SSM > Permissions
- AWS > SSM > Permissions > Levels
- AWS > SSM > Permissions > Levels > Modifiers
- AWS > SSM > Permissions > Lockdown
- AWS > SSM > Permissions > Lockdown > API Boundary
- AWS > SSM > Regions
- AWS > SSM > Stack
- AWS > SSM > Stack > Secret Variables
- AWS > SSM > Stack > Source
- AWS > SSM > Stack > Terraform Version
- AWS > SSM > Stack > Variables
- AWS > SSM > Tags Template [Default]
- AWS > Turbot > Event Handlers > Events > Rules > Custom Event Patterns > @turbot/aws-ssm
- AWS > Turbot > Permissions > Compiled > API Boundary > @turbot/aws-ssm
- AWS > Turbot > Permissions > Compiled > Levels > @turbot/aws-ssm
- AWS > Turbot > Permissions > Compiled > Service Permissions > @turbot/aws-ssm
Release Notes
5.14.0 (2023-01-05)
What's new?
AWS/SSM/Operator
andAWS/SSM/Metadata
now include permissions for SSM GUI Connect.
Action Types
Added
- AWS > SSM > Association > Delete from AWS
- AWS > SSM > Association > Skip alarm for Active control
- AWS > SSM > Association > Skip alarm for Active control [90 days]
- AWS > SSM > Association > Skip alarm for Approved control
- AWS > SSM > Association > Skip alarm for Approved control [90 days]
- AWS > SSM > Document > Delete from AWS
- AWS > SSM > Document > Set Tags
- AWS > SSM > Document > Skip alarm for Active control
- AWS > SSM > Document > Skip alarm for Active control [90 days]
- AWS > SSM > Document > Skip alarm for Approved control
- AWS > SSM > Document > Skip alarm for Approved control [90 days]
- AWS > SSM > Document > Skip alarm for Tags control
- AWS > SSM > Document > Skip alarm for Tags control [90 days]
- AWS > SSM > Maintenance Window > Delete from AWS
- AWS > SSM > Maintenance Window > Set Tags
- AWS > SSM > Maintenance Window > Skip alarm for Active control
- AWS > SSM > Maintenance Window > Skip alarm for Active control [90 days]
- AWS > SSM > Maintenance Window > Skip alarm for Approved control
- AWS > SSM > Maintenance Window > Skip alarm for Approved control [90 days]
- AWS > SSM > Maintenance Window > Skip alarm for Tags control
- AWS > SSM > Maintenance Window > Skip alarm for Tags control [90 days]
- AWS > SSM > Parameter > Delete from AWS
- AWS > SSM > Parameter > Set Tags
- AWS > SSM > Parameter > Skip alarm for Active control
- AWS > SSM > Parameter > Skip alarm for Active control [90 days]
- AWS > SSM > Parameter > Skip alarm for Approved control
- AWS > SSM > Parameter > Skip alarm for Approved control [90 days]
- AWS > SSM > Parameter > Skip alarm for Encryption at Rest control
- AWS > SSM > Parameter > Skip alarm for Encryption at Rest control [90 days]
- AWS > SSM > Parameter > Skip alarm for Tags control
- AWS > SSM > Parameter > Skip alarm for Tags control [90 days]
5.13.1 (2022-06-17)
Bug fixes
- The
AWS > SSM > Managed Instance > CMDB
control would incorrectly move to an error state while trying to fetch details for hybrid managed instances. This is now fixed.
5.13.0 (2022-03-31)
Resource Types
Added
- AWS > SSM > Managed Instance
Control Types
Added
- AWS > SSM > Managed Instance > CMDB
- AWS > SSM > Managed Instance > Discovery
Policy Types
Added
- AWS > SSM > Managed Instance > CMDB
- AWS > SSM > Managed Instance > Regions
Action Types
Added
- AWS > SSM > Managed Instance > Router
5.12.0 (2022-02-15)
What's new?
- Users can now create their own custom checks against resource attributes in the Approved control using the
Approved > Custom
policy. These custom checks would be a part of the evaluation of the Approved control. Custom messages can also be added which are then displayed in the control details table. See Custom Checks for more information.
Bug fixes
- We've improved the process of deleting resources from Turbot if their CMDB policy was set to
Enforce: Disabled
. The CMDB controls will now not look to resolve credentials via Turbot's IAM role while deleting resources from Turbot. This will allow the CMDB controls to process resource deletions from Turbot more reliably than before.
Policy Types
Added
- AWS > SSM > Association > Approved > Custom
- AWS > SSM > Document > Approved > Custom
- AWS > SSM > Maintenance Window > Approved > Custom
- AWS > SSM > Parameter > Approved > Custom
5.11.0 (2022-01-06)
What's new?
AWS/SSM/Admin
AWS/SSM/Metadata
now include permissions for Ops Metadata, Ops Item and Calendar State.
5.10.0 (2021-09-21)
Policy Types
Added
- AWS > SSM > Parameter > CMDB > Included Parameter Value Types
5.9.0 (2021-07-14)
What's new?
- We've improved the details tables in the Tags controls to be more helpful, especially when a resource's tags are not set correctly as expected. Previously, to understand why the Tags controls were in an Alarm state, you would need to find and read the control's process logs. This felt like too much work for a simple task, so now these details are visible directly from the control page.
5.8.0 (2021-06-24)
What's new?
AWS/SSM/Admin
now includes ops item, service setting, and session permissions.
5.7.2 (2021-06-07)
Bug fixes
- The
AWS > SSM > Document > CMDB
control will now also fetch the document's permission details and store them in CMDB.
5.7.1 (2021-04-13)
Bug fixes
- We’ve made a few improvements in the GraphQL queries for various controls, policies, and actions. You won’t notice any difference, but things should run lighter and quicker than before.
5.7.0 (2021-03-12)
What's new?
- We've improved the state reasons and details tables in various Approved and Active controls to be more helpful, especially when a resource is unapproved or inactive. Previously, to understand why one of these controls is in Alarm state, you would need to find and read the control's process logs. This felt like too much work for a simple task, so now these details are visible directly from the control page.
5.6.1 (2020-12-17)
Bug fixes
- We've updated various resources' Discovery and CMDB controls to ensure array properties are consistently sorted in the CMDB.
- Controls run faster now when in the
tbd
andskipped
states thanks to the new Turbot Precheck feature (not to be confused with TSA PreCheck). With Turbot Precheck, controls avoid running GraphQL input queries when intbd
andskipped
, resulting in faster and lighter control runs.
5.6.0 (2020-10-09)
What's new?
- Discovery controls now have their own control category,
CMDB > Discovery
, to allow for easier filtering separately from other CMDB controls.
Bug fixes
- The
AWS > SSM > Parameter > CMDB
control would sometimes fetch incorrect parameter data if multiple parameters existed with the same name. This is now fixed and theAWS > SSM > Parameter > CMDB
control will now store the data for the intended Parameter correctly. - We've made some improvements to our real-time event handling that reduces the risk of creating resources in CMDB with malformed AKAs. There's no noticeable difference, but things should run more reliably now.
5.5.2 (2020-08-14)
Bug fixes
- In various Active controls, we were outputting log messages that did not properly show how many days were left until we'd delete the inactive resources (we were still deleting them after the correct number of days). These log messages have been fixed and now contain the correct number of days.
5.5.1 (2020-08-10)
Bug fixes
- We now exclude the
ssm:UpdateInstanceAssociationStatus
API from the EventBridge rules as part of ongoing event handling improvements. This API is used frequently by AWS but is not valuable for Turbot to handle as it is not used for any current resource updates in CMDB.
5.5.0 (2020-07-20)
What's new?
- We’ve improved our event handling configuration and now filter which AWS events Turbot listens for based on resources’ CMDB policies. If a resource’s CMDB policy is not set to
Enforce: Enabled
, the EventBridge rules will be configured to not send any events for that resource. This will greatly reduce the amount of unnecessary events that Turbot listens for and handles today.
Policy Types
Added
- AWS > Turbot > Event Handlers > Events > Rules > Custom Event Patterns > @turbot/aws-ssm
Removed
- AWS > Turbot > Event Handlers > Events > Rules > Event Sources > @turbot/aws-ssm
5.4.2 (2020-07-07)
Bug fixes
- Updated various resource configurations to provide better compatibility with AWS China regions.
5.4.1 (2020-07-01)
Bug fixes
- Sometimes when updating CMDB for resources with tags that have empty string values, e.g.,
[{Key: "Empty", Value: ""}, {Key: "Turbot is great", Value: "true"}]
, we would not store all of the tags correctly. This has been fixed and now all tags are accounted for.
5.4.0 (2020-05-29)
Policy Types
Added
- AWS > SSM > Stack > Secret Variables
- AWS > SSM > Stack > Variables
5.3.1 (2020-05-26)
Policy Types
Renamed
- AWS > SSM > Association > Configured > Precedence to AWS > SSM > Association > Configured > Claim Precedence
- AWS > SSM > Document > Configured > Precedence to AWS > SSM > Document > Configured > Claim Precedence
- AWS > SSM > Maintenance Window > Configured > Precedence to AWS > SSM > Maintenance Window > Configured > Claim Precedence
5.3.0 (2020-05-15)
What's new?
- Updated
AWS > SSM > Regions
policy default value to now includeaf-south-1
,eu-south-1
.
5.2.0 (2020-04-23)
Control Types
Added
- AWS > SSM > Parameter > Encryption at Rest
Policy Types
Added
- AWS > SSM > Parameter > Approved > Parameter Type
- AWS > SSM > Parameter > Encryption at Rest
- AWS > SSM > Parameter > Encryption at Rest > Customer Managed Key
Action Types
Added
- AWS > SSM > Parameter > Update Encryption at Rest