Docs
Reference

AWS SSM Parameter Store

Move parameters to and from an SSM path.

Move parameters to and from an SSM path.

A newer connection reaches the same service: AWS SSM Parameter Store (IAM role).

The connection

WhatThis provider
VendorAmazon Web Services
Keyaws-ssm
Availabilityavailable. You can connect it today.
Credential penv holdsaws-iam
Values read backyes
Activationimmediate

What it moves

DirectionWhat it does
importReads names and values out of the store into penv.
exportWrites names and values from penv into the store.

When a written value goes live

immediate. The running app sees a new value at once.

What happens to a name that exists

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
accessKeyIdAccess key IDtextyes
secretAccessKeySecret access keysecret, masked here and sealedyes

What the connection asks for

Fixed when you connect, and shared by every mapping on it.

FieldLabelKindRequiredAdvancedWhat it is
regionRegiontextyesnoThe region this connection reaches. One connection covers one region.
accountIdAccount IDtextnoyesIf supplied, the generated policy names the account instead of a wildcard.
basePathBase pathtextyesnoThe widest SSM path this connection may touch. Every sync scope will sit under it.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
pathSSM pathtextyesnoMaps onto this environment. Will sit under the connection's base path.
recursiveInclude nested pathsyes or noyesyesNested SSM paths become the parameter's path prefix with us. Starts at true.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
sts:GetCallerIdentityevery directionyesWe cannot confirm which IAM identity this credential is.
ssm:GetParametersByPathevery directionyesPreview cannot list what is under this path.
kms:DecryptimportnoSecureString parameters will import empty
ssm:PutParameterexportyesExport cannot write anything.
kms:EncryptexportyesExport cannot write SecureString parameters.
ssm:DeleteParameterexportnoThe overwrite_and_prune policy cannot remove remote keys.