Skip to content
This repository has been archived by the owner on Nov 8, 2021. It is now read-only.

Alternative to import_users.sh for EC2 Instance Connect? #162

Open
bedge opened this issue Mar 29, 2021 · 3 comments
Open

Alternative to import_users.sh for EC2 Instance Connect? #162

bedge opened this issue Mar 29, 2021 · 3 comments

Comments

@bedge
Copy link

bedge commented Mar 29, 2021

This package now references "EC2 Instance Connect" as a replacement: https://aws.amazon.com/blogs/compute/new-using-amazon-ec2-instance-connect-for-ssh-access-to-your-ec2-instances/

However there's one component I don't see in 'EC2 Instance Connect` - the bulk import of IAM users into local users onto the AWS linux instance.

Is there some other mechanism that is intended to handle that function?

@michaelwittig
Copy link
Contributor

Hi @bedge
You are right. EC2 Instance Connect does not create local users for you. Feel free to continue to use this project if you need this capability.

@bedge
Copy link
Author

bedge commented Mar 30, 2021

@michaelwittig One more follow up if I may.
Given that EC2 Instance Connect also requires that users exist in IAM, it seems plausible that one could port the import_users.sh script from this package to fill in the missing piece.
From what I can tell you can't install both as they each need to control the sshd_config settings for AuthorizedKeysCommand

We have a mandate to rotate all ssh keys, so I'm wondering if a merging of the these to packages, even if only the import_users.sh script from here, might provide a complete solution.

@michaelwittig
Copy link
Contributor

I don't have an answer. Let's see if someone else has.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants