[英]cross account ssm start session
Was trying to start a session[terminal] via ssm on an instance in another account.试图通过 ssm 在另一个帐户的实例上启动会话 [终端]。 using command
使用命令
aws ssm start-session --target i-yyyaf4692d801d1xx --region ap-south-1
but it was failing with response as "Target is not connected".但由于“目标未连接”而无法响应。
END Goal: I wish to use users created in Account A to be able to start sessions on instances on Account B. both part of the same organisation. END 目标:我希望使用在帐户 A 中创建的用户能够在帐户 B 上的实例上启动会话。两者都是同一组织的一部分。
Also,还,
You need to delegate access between the accounts.您需要在帐户之间委派访问权限。 You can do this by creating a role in the target account which is allowed to assumed by users in the other account.
您可以通过在目标账户中创建一个允许其他账户中的用户担任的角色来执行此操作。
Setup the access:设置访问:
Use the access:使用访问权限:
See: cross-account IAM access for more details.请参阅: 跨账户 IAM 访问以获取更多详细信息。
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.