Minimal non-root no-shell container image for managing AWS SSM sessions
308
aws-ssm-minimal is a purpose-built container image for running the AWS Systems Manager (SSM) agent as a sidecar in compute environments that do not ship with SSM pre-installed (for example, ECS Fargate tasks, EKS Pods, or plain OCI runtimes). The image bundles:
aws/amazon-ssm-agent compiled directly in the Docker build.FROM scratch).TTL_SECONDS (default 3600) to have the sidecar gracefully shut down after a fixed lifetime. TTL_SHUTDOWN_GRACE_SECONDS (default 15) controls how long to wait after sending SIGTERM before force killing the agent.scratch with only the compiled binaries and certificates. Ideal for sidecar deployments where resource overhead matters.Environment variables:
MANAGED_INSTANCE_ROLE_NAME (required) – IAM role name to associate with the managed instance. Attach the standard AmazonSSMManagedInstanceCore policy (plus any extra permissions your sessions need).TTL_SECONDS – Runtime lifetime in seconds before the wrapper initiates shutdown (default 3600).TTL_SHUTDOWN_GRACE_SECONDS – Grace period between sending SIGTERM and SIGKILL to the agent (default 15).{
"name": "eks-private-access",
"image": "ghcr.io/your-org/aws-ssm-minimal:latest",
"essential": false,
"environment": [
{ "name": "MANAGED_INSTANCE_ROLE_NAME", "value": "MyManagedInstanceRole" },
{ "name": "TTL_SECONDS", "value": "1800" }
]
}
Required IAM permissions for the task role:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ssm:CreateActivation",
"ssm:DeleteActivation",
"ssm:DeregisterManagedInstance"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": "iam:PassRole",
"Resource": "arn:aws:iam::<account-id>:role/MyManagedInstanceRole"
}
]
}
Managed instance role:
ssm.amazonaws.com in its assume-role policy.AmazonSSMManagedInstanceCore (plus any custom permissions you require for the session).docker pull benwsapp/aws-ssm-minimal:latestMANAGED_INSTANCE_ROLE_NAME.File GitHub issues for bugs or feature requests at your repository hosting this Dockerfile. This image is not an official AWS distribution but compiles the OSS agent directly from Amazon’s source.
Content type
Image
Digest
sha256:1c7c33770…
Size
46.9 MB
Last updated
12 months ago
docker pull benwsapp/aws-ssm-minimal:dev