Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
GitHub Actions can SSH to a private EC2 instance without an inbound port 22 rule by using GitHub OIDC for short-lived AWS credentials and AWS Systems Manager Session Manager as the connection path. The SSH connection still uses an OS account and its associated SSH key; Session Manager supplies the tunnel, not a replacement for SSH authentication.
How the connection works
The workflow first exchanges a GitHub-issued OIDC token for temporary AWS credentials by assuming an IAM role. It then runs SSH through an AWS CLI ProxyCommand that starts an AWS-StartSSHSession Session Manager session to the EC2 instance. The target instance must be registered as an SSM managed node, reachable by Systems Manager, and running SSH. The workflow needs the appropriate SSH private key and OS username.
This removes the need for a network path from the GitHub runner to the instance’s TCP port 22. It does not disable SSH on the instance or remove the SSH key requirement. AWS documents this pattern in Allow and control permissions for SSH connections through Session Manager.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What you need before configuring the workflow
- An SSM-managed EC2 instance: The instance must be managed by Systems Manager, and its network setup must allow it to reach the Systems Manager endpoints. The precise instance role, endpoint, subnet, and egress configuration depends on your AWS architecture.
- SSH on the instance: The SSH service must be running, and the selected OS account must accept the public key corresponding to the private key used by the workflow.
- Tools on the runner: Install the AWS CLI and Session Manager plugin in the runner environment. AWS lists the plugin as a prerequisite for starting sessions in its Session Manager plugin installation guide.
- Scoped IAM access: The assumed role needs permission to start the intended session. Scope permissions to the necessary instance and session document where supported; avoid granting unrestricted access to all instances or session documents.
- A protected SSH key: Make the private key available to the workflow through an appropriate secret-management process, and limit which jobs can access it. OIDC removes the need for long-lived AWS access keys in GitHub secrets; it does not make an SSH key unnecessary.
Set up GitHub OIDC access to AWS
Configure an IAM OIDC identity provider for GitHub and create a role that the workflow can assume. Use the audience sts.amazonaws.com when using GitHub’s official AWS credentials action. Most importantly, constrain the role’s trust policy with conditions so only the intended repository and branch, tag, or GitHub environment can assume it. GitHub warns that conditions are required to prevent untrusted repositories from requesting tokens. See GitHub’s AWS OIDC configuration guide.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Grant the role only the Systems Manager permissions needed for this connection and the intended target. Exact policy resources and conditions depend on the AWS operation and account setup; validate the policy against the specific role, instance, and session document rather than using a broad wildcard as a production shortcut.
Configure SSH to use Session Manager
In the runner’s SSH configuration, set a ProxyCommand that starts a Session Manager SSH session. AWS documents this command pattern:
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
aws ssm start-session --target %h --document-name AWS-StartSSHSession --parameters 'portNumber=%p'
Here, %h is the SSH host (set it to the EC2 instance identifier for this pattern), and %p is the SSH port. A corresponding SSH invocation must use the intended operating-system username and private key, for example:
Recommended Free Tools
ssh -i /path/to/private-key.pem ec2-user@i-0123456789abcdef0
Replace the example username, key path, and instance identifier with values appropriate to the instance and runner. Configure the SSH host entry or equivalent invocation so the ProxyCommand above is used. The key must match a public key accepted by the selected OS account. Do not add a security-group ingress rule for TCP 22 from GitHub-hosted runner address ranges to make this route work; the connection uses Systems Manager rather than an inbound SSH connection to the instance.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Choose the right Systems Manager connection method
| Method | Best suited to | Target and authentication | Important distinction |
|---|---|---|---|
| SSH through Session Manager | Running SSH commands or using SSH-based deployment tools on the EC2 host | SSH must run on the instance; authenticate as an OS user with an SSH key. IAM authorizes the Session Manager session. | Uses the AWS-StartSSHSession document and keeps SSH authentication in place. |
| Session Manager port forwarding | Connecting to a TCP service on the managed node or a remote host without exposing an inbound port | IAM authorizes a tunnel to a port; the service being accessed must be listening and reachable from the forwarding target. | For forwarding to the managed node, AWS lists SSM Agent 2.3.672.0 as the minimum; forwarding to a remote host requires 3.1.1374.0. See AWS Session Manager session documentation. |
| Systems Manager Run Command | A task that only needs to execute commands on a managed node | Uses Systems Manager command execution rather than an interactive SSH connection. | It is a separate operation from SSH tunneling; determine its specific permissions and operational behavior for your workflow before adopting it. |
Port forwarding is not the same as SSH over Session Manager. AWS describes forwarding as a way to reach private VPC resources without opening inbound ports, requiring SSH keys for the tunnel, or configuring a bastion for that forwarding path. That does not remove the SSH-key requirement when the chosen method is SSH through Session Manager.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Plan for the Session Manager logging limitation
AWS states: “Logging isn’t available for Session Manager sessions that connect through port forwarding or SSH.” With SSH or port forwarding, the encrypted payload is carried inside the TLS connection and Session Manager acts as a tunnel, so Session Manager cannot record the session contents. A team that needs command-level audit evidence should account for that limitation in its audit design rather than treating Session Manager session logging as a transcript of SSH activity.
Quick Recap
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Workflow checks when the connection fails
- Session cannot start: Check that the instance appears as an SSM managed node, the runner has the AWS CLI and Session Manager plugin, and the assumed role can start the intended session against that target.
- SSH authentication fails: Verify the SSH username and private key, confirm the matching public key is authorized for that OS account, and check that SSH is running on the instance.
- The workflow assumes the wrong role or cannot assume one: Check the OIDC provider, the
sts.amazonaws.comaudience, and the trust-policy conditions for the repository and intended branch, tag, or environment. - The instance is not reachable through Systems Manager: Review its SSM management and network connectivity to Systems Manager endpoints. The needed network path varies by account architecture.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

