Recommended update for amazon-ssm-agent

Announcement ID: SUSE-RU-2018:3310-1
Rating: moderate
References:
Affected Products:
  • Public Cloud Module 12
  • SUSE Linux Enterprise High Performance Computing 12 SP2
  • SUSE Linux Enterprise High Performance Computing 12 SP3
  • SUSE Linux Enterprise High Performance Computing 12 SP4
  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise Server 12
  • SUSE Linux Enterprise Server 12 SP1
  • SUSE Linux Enterprise Server 12 SP2
  • SUSE Linux Enterprise Server 12 SP3
  • SUSE Linux Enterprise Server 12 SP4
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server for SAP Applications 12
  • SUSE Linux Enterprise Server for SAP Applications 12 SP1
  • SUSE Linux Enterprise Server for SAP Applications 12 SP2
  • SUSE Linux Enterprise Server for SAP Applications 12 SP3
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5

An update that has one fix can now be installed.

Description:

This update for amazon-ssm-agent provides version 2.3.50.0 and fixes the following issues:

  • Enables the Session Manager capability that lets you manage your Amazon EC2 instance through an interactive one-click browser-based shell or through the AWS CLI.
  • Beginning this agent version, SSM Agent will create a local user "ssm-user" and add it to /etc/sudoers (Linux) every time the agent starts. The ssm-user is the default OS user when a Session Manager session is started, and the password for this user is reset on every session. You can change the permissions by moving the ssm-user to a less-privileged group or by changing the sudoers file. The ssm-user is not removed from the system when SSM Agent is uninstalled.
  • Retry sending Run Command execution results for up to 2 hours.
  • More detailed error messages are returned for inventory plugin failures during State Manager association executions.
  • Bug fix to clean the orchestration directory.
  • Streaming AWS Systems Manager Run Command output to CloudWatch Logs.
  • Reducing number of retries for serial port opening.
  • Add retry logic to installation verification.
  • Bug fix to retry sending document results if they couldn't reach the service.
  • Bug fix so that aws:downloadContent does not change permissions of directories.
  • Bug fix to Cloudwatch plugin where StartType has duplicated Enabled value.
  • Added support for agent hibernation so that Agent backs off or enters hibernation mode if it does not have access to the service.
  • Fix S3Download to download from cross regions.

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • Public Cloud Module 12
    zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2018-2386=1

Package List:

  • Public Cloud Module 12 (aarch64 ppc64le s390x x86_64)
    • amazon-ssm-agent-2.3.50.0-4.18.1

References: