Mgmt & Governance
AWS Systems Manager
AWS Systems Manager is an operations suite for managed nodes and AWS resources, including inventory, Session Manager, Run Command, Automation, Patch Manager, State Manager, Parameter Store, Change Manager, Quick Setup and operational dashboards.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Systems Manager.
AWS Systems Manager pricing and cost programs
Pricing model: Feature-specific management usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Managed nodes · Automation steps · Parameters · OpsCenter and incident features
Programs and modes: Standard and advanced managed nodes · Parameter Store · Automation · AppConfig
Many Systems Manager features have separate included tiers or metered dimensions.
Free Tier: Service-specific — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement AWS Systems Manager?
- Replaces many bastion, SSH-key, remote-shell, patch-orchestration and configuration-script servers with managed control-plane workflows.
- Operates EC2, edge and hybrid managed nodes at fleet scale through service roles, the Systems Manager agent and VPC endpoints or internet connectivity.
- Provides logged sessions, commands, automation documents, maintenance windows, inventory, patch policies, parameters and cross-account Quick Setup capabilities.
How to implement AWS Systems Manager
- Define accounts, Regions, node enrollment, network endpoints, agent lifecycle, operator personas, approval, logging, encryption, patch groups, maintenance windows, concurrency, error thresholds, rollback and emergency access.
- Use Default Host Management Configuration or narrowly scoped instance profiles, deploy current agents, create Session Manager preferences, organization Quick Setup patch policies, versioned Automation documents and least-privilege parameter access.
- Canary every document and patch baseline, limit concurrency and errors, stream logs to protected CloudWatch Logs or S3, monitor association and command failures, inventory unmanaged nodes, and regularly test emergency and recovery procedures.
AWS Systems Manager best practices
- Prefer Session Manager over inbound SSH or RDP, remove public administration ports and shared keys, require individual federated identities, and record sessions when application and privacy requirements allow.
- Use Quick Setup patch policies for organization-wide patching, stage rings before production, define maintenance and reboot behavior, and measure actual compliance rather than only successful command submission.
- Never pass plaintext secrets through Run Command because parameters and output can appear in CloudTrail, S3 or logs; retrieve SecureString or Secrets Manager values at runtime under the managed node's scoped identity.
AWS Systems Manager use cases and server impact
- Private shell access without bastions
- Fleet patching and desired-state enforcement
- Audited operational runbooks and remote commands
Replaces bastions and much fleet-management, patch and runbook infrastructure, while node enrollment, agent health, IAM, document safety, maintenance impact, application validation, logging and exception handling remain yours.
Official implementation resources
Commonly paired AWS services
- Amazon Elastic Compute Cloud — Resizable virtual servers
- AWS Identity and Access Management — Identity & access
- AWS Key Management Service — Key management
- Amazon CloudWatch — Metrics & logs
- Amazon Simple Storage Service — Object storage
- AWS Config — Resource compliance
- AWS Secrets Manager — Store secrets & keys
- AWS Organizations — Multi-account mgmt
Planning guides that use AWS Systems Manager
- AWS AppConfig planning guide — Use Systems Manager as the broader management service that includes AWS AppConfig.