Amazon EC2 · Finder + automated fixer

EC2 Install SSM Agent on Linux/Mac

InstallSSM Agent on Linux/Mac

Install the AWS SSM Agent on Linux and Mac EC2 instances via SSH. CloudFix detects instances without SSM Agent and installs it for fleet management.

What happens, in order.

  1. Finder · read-only

    Finds the opportunity

    Scans your connected accounts with a read-only role. It can see resource metadata and usage; it can’t change anything.

  2. You

    Approve in Recommendations

    It appears in your Recommendations view with what it would save. Approve the resources you choose. Nothing has changed yet.

  3. Fixer

    Runs in your account

    The fixer runs as an AWS Systems Manager Automation runbook in your AWS account, and acts only on the resources you approved.

  4. Record

    Logs the execution

    The Systems Manager execution is logged, so every change can be audited.

Finder role

Read-only. It can see resource metadata and usage. It can’t change anything.

Fixer role

A separate, minimal role that acts only on the resources you approved, through AWS Systems Manager.

Saves by

Correctly rightsizing or retyping an EC2 instance requires knowing how the instance is used. By default, AWS provides metrics on CPU utilization but not on memory and disk utilization. To capture these metrics, we need the CW agent installed on the instance. The right way to install CW agents is via SSM state associations, for which we need the SSM agent installed first.

For comprehensive management and monitoring of your EC2 instances, the AWS Systems Manager (SSM) agent is essential. However, many legacy or custom instances may not have this agent installed or properly configured. This CloudFix Finder/Fixer automatically identifies Linux and macOS instances without functioning SSM agents and securely installs or activates them using EC2 Instance Connect, enabling advanced cost optimization opportunities.

Overview

Problem Statement

Accurately optimizing EC2 instances requires comprehensive usage data, including memory and disk utilization metrics that aren’t available by default. To collect this data, the CloudWatch agent must be installed and configured properly, which in turn depends on having a functional SSM agent. Many EC2 instances, especially custom or older AMIs, don’t have the SSM agent installed or may have it installed but not running. Without this critical component, cost optimization efforts are limited to basic CPU metrics, potentially leaving significant savings opportunities undiscovered.

Solution & Benefits

CloudFix systematically identifies Linux and macOS EC2 instances without functioning SSM agents and uses an innovative, secure approach to install or activate them without downtime. By leveraging EC2 Instance Connect to create temporary, secured SSH access, CloudFix can remotely install the appropriate SSM agent version for your specific operating system, enabling advanced management capabilities and unlocking additional cost optimization opportunities.

  • Enables comprehensive instance monitoring and management
  • Unlocks additional cost optimization opportunities
  • Operates without downtime or service interruption
  • Creates a backup snapshot for added safety
  • Uses secure, temporary access that automatically expires
  • Supports a wide range of Linux distributions and macOS versions

Expected Cost Savings

While this Finder/Fixer doesn’t directly generate cost savings, it’s a critical enabler for other CloudFix optimizations. Once the SSM agent is installed, CloudFix can deploy the CloudWatch agent to collect memory and disk utilization metrics, providing the complete data needed for accurate instance rightsizing and optimization recommendations. That data is what lets the downstream rightsizing recommendations be made with confidence.

AWS Services Affected

This CloudFix feature interacts with the following AWS services:

How It Works

The CloudFix Finder works read-only, using your AWS usage data and Systems Manager status to identify standalone Linux and macOS instances where the SSM agent is missing or not running. Each instance appears in your Recommendations, and nothing changes until you approve it.

Once approved, the Fixer runs in your own AWS account. It takes a backup snapshot of the instance, then uses EC2 Instance Connect’s short-lived, secure access to install or start the right SSM agent for the operating system, and confirms the instance now reports to Systems Manager. Every execution is logged, and no downtime is required.

FAQ

Q: Will implementing this fix require downtime for my EC2 instances?

No, this fix is implemented without any downtime or service interruption. The SSM agent installation happens in the background while your instance continues to operate normally.

Q: Is this process secure?

Yes. CloudFix uses EC2 Instance Connect’s secure, temporary access mechanism. The access expires automatically within moments and is never stored, and the temporary components used for the installation run inside your own account and are removed as soon as the operation is complete.

Q: What if something goes wrong during the installation?

CloudFix creates a snapshot of your instance before making any changes. In the unlikely event of a problem, this snapshot can be used to restore the instance to its previous state. The snapshot is cleaned up automatically after a successful fix.

Q: Which operating systems are supported?

This Finder/Fixer supports most common Linux distributions (Amazon Linux, Amazon Linux 2, Ubuntu, CentOS, RHEL, etc.) and macOS instances. Windows instances are not supported by this particular Finder/Fixer but are covered by a separate CloudFix feature.

Q: Why doesn’t CloudFix use AWS-native mechanisms to install the SSM agent?

AWS provides several ways to install the SSM agent, but most require either the agent to already be installed (State Manager) or instance downtime (userdata). CloudFix’s approach works on running instances without disruption, making it ideal for production environments.


Ready to start saving on AWS? See how much you could cut from your cloud bill with a free cost optimization assessment, or explore CloudFix automated Finder/Fixers that eliminate waste across 30+ AWS services.

Related Articles

See whether this one applies to your account.

A free savings assessment reports which fixers can be applied to your environment. Results typically within 24 hours.