$ cat blog/aws-patch-management
Back to Blog
Cloud Security••4 min read

Golden AMIs on AWS: From Setup to Automated Patch Cycle

What a Golden AMI is, why it beats manual patching, and the actual AWS Systems Manager steps to build and automate one end to end.

Manual patching is a time sink, and a liability when patches slip through the cracks. Golden AMIs and AWS Systems Manager let you bake security into your server baseline and automate the rest.

What a Golden AMI Is

A Golden AMI is a pre-configured server image: all the necessary software installed, security patches applied, settings locked in. It's the master blueprint every new instance launches from, instead of each server getting configured by hand.

AWS Systems Manager is what keeps that blueprint current. It can apply patches automatically and generate new AMI versions from your Golden AMI baseline, so you're not manually rebuilding the image every time something needs updating.

Why This Setup Works

  • Fewer vulnerabilities in production. A standardized, regularly patched baseline means new instances don't inherit month-old gaps.
  • Less manual effort. Automation replaces the repetitive work of configuring and patching each server individually.
  • Scales cleanly. New instances launched from the Golden AMI inherit the current configuration and security posture automatically, no matter how many you need.

Setup takes a few hours upfront. You pay that cost once instead of on every patch cycle.

Prerequisites

  • An AWS account with permissions for EC2, Systems Manager, and related services.
  • Familiarity with Systems Manager's Automation, Patch Manager, and Parameter Store components.
  • A standardized process for what software and configuration belong on your servers in the first place.

Step 1: Create the Golden AMI

  1. Launch a base EC2 instance on an AMI appropriate for your OS and workload.
  2. Install required software, apply all current security patches, and configure system settings (networking, application config, etc.).
  3. Test the instance: confirm it works as expected and run a vulnerability scan against it.
  4. Stop the instance and create an AMI from it. Name it clearly (Golden-AMI-<version>) so version tracking doesn't become guesswork later.

Step 2: Automate Updates to the Golden AMI

  1. In Systems Manager's Automation section, create an Automation Document (e.g., UpdateGoldenAMI) that launches the Golden AMI in a temporary instance, applies the latest patches and updates, and creates a new AMI from the result.
  2. Schedule that document to run on a regular cadence (weekly or monthly) using Systems Manager's cron-like scheduling.
  3. Store the current Golden AMI's ID in Parameter Store, and update that entry every time a new version is created, so anything referencing "the latest AMI" stays accurate automatically.

Step 3: Deploy New Instances from the Golden AMI

  1. Pull the current AMI ID from Parameter Store.
  2. Launch new instances from it, whether manually or through an auto-scaling group, and make sure both paths are actually pointed at the latest version.
  3. Apply any instance-specific configuration with State Manager or startup scripts after launch.

Step 4: Manage Ongoing Patching

  1. Use Patch Manager to define Patch Groups based on server role or environment, and tag EC2 instances accordingly.
  2. Build custom patch baselines per group, specifying which patches are approved and what compliance looks like for that group.
  3. Set maintenance windows and configure Systems Manager to apply patches during them.

Step 5: Automate the Instance Lifecycle

  1. Configure Auto Scaling to launch new instances from the current Golden AMI automatically.
  2. Use EC2 lifecycle hooks to trigger configuration updates or other actions at launch and termination.

Resources

Golden AMIs give you a tested, patched baseline so new instances don't inherit month-old vulnerabilities. Automation handles the toil, and auto scaling picks up the latest image automatically. Adapt the steps to your own environment, and you'll have a repeatable, defensible process for keeping your AWS fleet current.

Jonathan Carpenter
Jonathan Carpenter
Founder, Anchor Cyber Security
Share:

Want to discuss this topic?

Let's talk about how these insights apply to your organization.

Get in Touch