Can't run remote PowerShell commands in custom CloudFormation AMI (WinServer 2012)

Viewed 95

The issue I'm going to describe works OK on a stock Windows Server 2012 AMI from Amazon. I'm facing issues with a custom AMI.

I created a custom AMI for Windows Server 2012 by creating an image from an EC2 machine.

Just before creating the custom AMI, I used the Ec2ConfigServiceSetting.exe to make sure:

  • The instance receives a new machine name based on its IP.
  • The password of the user is changed on boot.
  • The instance is provisioned using the script I have in place in UserData.

I also shut down the instance using Sysprep from the Ec2ConfigServiceSetting before creating the image for the custom AMI.

However, when I run a remote PowerShell command (from C# code, if it matters), it doesn't work. From C#-land, the command gets executed OK, but nothing happens in the machine.

Let's say my remote PS command launches a program in the remote machine (agent.exe). My script looks a little bit like:

Set-Location C:\path\in\disk
$env:Path = "C:\some\thing;" + $env:Path
C:\path\to\agent.exe --daemon

Once I log into the Ec2 instance, agent.exe --daemon is NOT running. However, if I first log into the instance, then run the remote PowerShell command, agent.exe --daemon DOES run.

This works perfectly with a stock AMI from Amazon, so I can only assume there's some configuration I'm missing for this to work (and, why does it work if I first log in using RDesktop?)

We found in the past some issues regarding SSL initialization without a user profile, so in our provisioning script (UserData) we do some things someone might consider shenanigans:

net user Administrator hardcoded-password
net user ec2-user hardcoded-password /add

$pwd = (ConvertTo-SecureString 'hardcoded-password' -AsPlainText -Force)
$cred = New-Object System.Management.Automation.PSCredential('Administrator', $pwd)
Start-Process cmd -LoadUserProfile -Credential $cred
0 Answers
Related