EC2 Gateways
Last modified on March 24, 2023
The StrongDM gateway works with any Linux distribution and any server with two CPUs and four gigabytes of memory.
Launch an EC2 instance: we recommend a t3.medium (2 vCPU, 4 GB RAM) with any Linux distribution.
Modify the security group to allow your StrongDM clients to reach this server. By default this is port 5000 from all sources. This can also be a custom port from a private subnet depending on your network configuration.Navigate to the StrongDM Admin UI.
Select the Gateways tab and click add gateway.

Copy the hostname or IP address from the EC2 instance and paste it into the advertised host. The hostname that you provide should be either the public IPv4 address or the external DNS hostname (which will resolve to the public IPv4 address).
Enter the port that you left open for the gateway to interact with StrongDM clients (by default,
5000
).Click create. This generates a token which is only shown to you one time that you’ll need to use later in the installation process. Carefully copy the token and save it somewhere for later use.
Log in to the EC2 instance you created to host your gateway.
Download the StrongDM binary:
curl -J -O -L https://app.strongdm.com/releases/cli/linux
Unzip it (if this is a new server, you may need to install a package to unzip archives, such as with
sudo apt-get install unzip
on Ubuntu distributions):unzip sdmcli_VERSION_NUMBER_linux_amd64.zip
Install the gateway:
sudo ./sdm install --relay
You will be prompted for the token you created above; paste it in and hit enter. Note that the token won’t show in the terminal for security purposes, similar to the masking of a password.
/etc/passwd
file. Any users remotely authenticated, such as with LDAP or an SSO service, may fail to complete the installation.- Switch back to the StrongDM Admin UI. In the Gateways tab, the gateway you created should appear to be online, and have a heartbeat. If it doesn’t appear online, perform a hard refresh of your browser. Within a couple of minutes, if it is still not online, verify that the StrongDM daemon is running by running
ps aux|grep sdm
on the server and looking for a line that sayssdm relay
.
If you have problems, contact StrongDM support.