Setting up Amazon Systems Manager for edge devices - Amazon Systems Manager
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China.

Setting up Amazon Systems Manager for edge devices

This section describes the setup tasks that account and system administrators perform to enable configuration and management of Amazon IoT Greengrass core devices. After you complete these tasks, users who have been granted permissions by the Amazon Web Services account administrator can use Amazon Systems Manager to configure and manage their organization's Amazon IoT Greengrass core devices.

Note
  • SSM Agent for Amazon IoT Greengrass isn't supported on macOS and Windows 10. You can't use Systems Manager capabilities to manage and configure edge devices that use these operating systems.

  • Systems Manager also supports edge devices that aren't configured as Amazon IoT Greengrass core devices. To use Systems Manager to manage Amazon IoT Core devices and non-Amazon edge devices, you must configure them as on-premises machines in a hybrid environment. For more information, see Setting up Amazon Systems Manager for hybrid environments.

  • To use Session Manager and Microsoft application patching with your edge devices, you must enable the advanced-instances tier. For more information, see Turning on the advanced-instances tier.

Before you begin

Verify that your edge devices meet the following requirements.

  • Your edge devices must meet the requirements to be configured as Amazon IoT Greengrass core devices. For more information, see Setting up Amazon IoT Greengrass core devices in the Amazon IoT Greengrass Version 2 Developer Guide.

  • Your edge devices must be compatible with Amazon Systems Manager Agent (SSM Agent). For more information, see Supported operating systems.

  • Your edge devices must be able to communicate with the Systems Manager service in the cloud. Systems Manager doesn't support disconnected edge devices.

About setting up edge devices

Setting up Amazon IoT Greengrass devices for Systems Manager involves the following processes.

Step Details

Step 1: Complete general Systems Manager setup steps

Complete all of the general requirements for setting up and configuring Systems Manager. If you completed these steps already, see Step 2.

Step 2: Create an IAM service role for edge devices

Create an Amazon Identity and Access Management (IAM) service role that enables your Amazon IoT Greengrass devices to communicate with Systems Manager. If you previously configured on-premises servers and virtual machines in a hybrid environment for Systems Manager then you might have completed this step already.

Step 3: Set up Amazon IoT Greengrass

You must set up your edge devices as Amazon IoT Greengrass core devices. The setup process involves verifying supported operating systems and system requirements, as well as installing and configuring the Amazon IoT Greengrass Core software on your devices. For more information, see Setting up Amazon IoT Greengrass core devices in the Amazon IoT Greengrass Version 2 Developer Guide.

Step 4: Update the Amazon IoT Greengrass token exchange role and install SSM Agent on your edge devices

The final step for setting up and configuring your Amazon IoT Greengrass core devices for Systems Manager requires you to update the Amazon IoT Greengrass IAM service role, also called the token exchange role, and deploy Amazon Systems Manager Agent (SSM Agent) to your Amazon IoT Greengrass devices. Both processes are described in detail in the Amazon IoT Greengrass Version 2 Developer Guide. For more information, see Install Amazon Systems ManagerSSM Agent.

Amazon Systems Manager Agent (SSM Agent) makes it possible for Systems Manager to update, manage, and configure your edge devices. To deploy SSM Agent to your Amazon IoT Greengrass devices, use Greengrass to deploy the aws.greengrass.SystemsManagerAgent component to your devices. After you deploy SSM Agent to your devices, Amazon IoT Greengrass automatically registers your devices with Systems Manager. No additional registration is necessary. You can begin using Systems Manager capabilities to access, manage, and configure your Amazon IoT Greengrass devices.

Note

For information about uninstalling SSM Agent from an edge device, see Uninstall the Amazon Systems Manager Agent in the Amazon IoT Greengrass Version 2 Developer Guide.