An extra 30% off every course until Sunday, October 11.Choose your certification →

Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.2.1.3. Configuration Management Services & Strategies

2.2.1.3. Configuration Management Services & Strategies

Configuration management ensures that every server, container, and service is configured consistently and stays that way. The challenge isn't the initial setup — it's preventing drift over months of patches, hotfixes, and manual changes.

AWS Systems Manager State Manager enforces desired-state configuration by applying associations on a schedule. An association links a target (EC2 instances by tag, all instances, specific instance IDs) to an SSM document that defines the desired state. Tag-based targets also cover instances launched later, which receive the configuration when they come online. If an instance drifts, State Manager reapplies the configuration automatically.

AWS OpsWorks provided managed Chef and Puppet, running recipes/manifests at lifecycle events (setup, configure, deploy, undeploy, shutdown). It reached end of life in 2024 (OpsWorks for Puppet Enterprise on March 31, OpsWorks for Chef Automate on May 5, OpsWorks Stacks on May 26). Teams with existing Chef cookbooks or Ansible playbooks now run them through State Manager associations (AWS-ApplyChefRecipes, AWS-ApplyAnsiblePlaybooks) with no configuration server to operate.

Elastic Beanstalk environments are customized with .ebextensions/*.config files in the source bundle (packages, files, commands, container_commands, option_settings) — version-controlled and applied on every deploy, including to instances launched by scaling.

AWS AppConfig manages application configuration (feature flags, tuning parameters) separately from infrastructure. It deploys configuration changes with safety controls — gradual rollout, automatic rollback on CloudWatch alarm breach, and validation via Lambda or JSON schema.

# SSM State Manager: Ensure CloudWatch agent is always running
aws ssm create-association \
  --name "AWS-ConfigureAWSPackage" \
  --targets "Key=tag:Environment,Values=Production" \
  --parameters '{"action":["Install"],"name":["AmazonCloudWatchAgent"]}' \
  --schedule-expression "rate(1 day)"

Exam Trap: State Manager associations run on a schedule — they don't prevent drift in real-time. For immediate drift detection and remediation, use AWS Config rules with automatic remediation via SSM Automation. State Manager is for enforcing desired state; Config is for detecting deviations.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications