Setting up Amazon Systems Manager for edge devices
This section describes the setup tasks that account and system administrators perform to enable configuration and management of Amazon IoT Greengrass core devices. After you complete these tasks, users who have been granted permissions by the Amazon Web Services account administrator can use Amazon Systems Manager to configure and manage their organization's Amazon IoT Greengrass core devices.
-
SSM Agent for Amazon IoT Greengrass isn't supported on macOS and Windows 10. You can't use Systems Manager capabilities to manage and configure edge devices that use these operating systems.
-
Systems Manager also supports edge devices that aren't configured as Amazon IoT Greengrass core devices. To use Systems Manager to manage Amazon IoT Core devices and non-Amazon edge devices, you must configure them as on-premises machines in a hybrid environment. For more information, see Setting up Amazon Systems Manager for hybrid environments.
-
To use Session Manager and Microsoft application patching with your edge devices, you must enable the advanced-instances tier. For more information, see Turning on the advanced-instances tier.
Before you begin
Verify that your edge devices meet the following requirements.
-
Your edge devices must meet the requirements to be configured as Amazon IoT Greengrass core devices. For more information, see Setting up Amazon IoT Greengrass core devices in the Amazon IoT Greengrass Version 2 Developer Guide.
-
Your edge devices must be compatible with Amazon Systems Manager Agent (SSM Agent). For more information, see Supported operating systems.
-
Your edge devices must be able to communicate with the Systems Manager service in the cloud. Systems Manager doesn't support disconnected edge devices.
About setting up edge devices
Setting up Amazon IoT Greengrass devices for Systems Manager involves the following processes.
Step | Details |
---|---|
Complete all of the general requirements for setting up and configuring Systems Manager. If you completed these steps already, see Step 2. |
|
Create an Amazon Identity and Access Management (IAM) service role that enables your Amazon IoT Greengrass devices to communicate with Systems Manager. If you previously configured on-premises servers and virtual machines in a hybrid environment for Systems Manager then you might have completed this step already. |
|
You must set up your edge devices as Amazon IoT Greengrass core devices. The setup process involves verifying supported operating systems and system requirements, as well as installing and configuring the Amazon IoT Greengrass Core software on your devices. For more information, see Setting up Amazon IoT Greengrass core devices in the Amazon IoT Greengrass Version 2 Developer Guide. |
|
The final step for setting up and configuring your Amazon IoT Greengrass core devices for Systems Manager requires you to update the Amazon IoT Greengrass IAM service role, also called the token exchange role, and deploy Amazon Systems Manager Agent (SSM Agent) to your Amazon IoT Greengrass devices. Both processes are described in detail in the Amazon IoT Greengrass Version 2 Developer Guide. For more information, see Install Amazon Systems ManagerSSM Agent. Amazon Systems Manager Agent
(SSM Agent) makes it possible for Systems Manager to update, manage, and configure
your edge devices. To deploy SSM Agent to your Amazon IoT Greengrass devices, use
Greengrass to deploy the |
For information about uninstalling SSM Agent from an edge device, see Uninstall the Amazon Systems Manager Agent in the Amazon IoT Greengrass Version 2 Developer Guide.
Topics