Use SSM In Leaf RI VPC

We have a successful deployment of the Leaf RI into a GovCloud account. I am trying to stand up a new instance in the same VPC in the public subnet and I would like to connect to it with SSM Session Manager. The instance has a public IP, and it does successfully stand up. The IAM role attached has the AmazonSSMManagedInstanceCore policy. The subnet looks normal to me in that it has an IGW, Network ACL looks normal, and the route has a destination of 0 to the IGW.

All this said, I can’t connect to it from SSM. It appears to be unable to hit the SSM public endpoint. Is there something I am supposed to do in order to facilitate this? Here’s a timeout response from when I used EC2 Instance connect and tried to hit SSM:

telnet ssm.us-gov-east-1.amazonaws.com 443
Trying 10.0.29.101...
^C
[root@ip-10-0-0-208 ~]# ping 10.0.29.101
PING 10.0.29.101 (10.0.29.101) 56(84) bytes of data.
^C
--- 10.0.29.101 ping statistics ---
10 packets transmitted, 0 received, 100% packet loss, time 9196ms
[root@ip-10-0-0-208 ~]# 
Entering SSM Agent hibernate - RequestError: send request failed
caused by: Post "https://ssm.us-gov-east-1.amazonaws.com/": dial tcp 10.0.47.124:443: i/o timeout

HI Ben,

Do you have the ssm endpoint security group added to all the node groups?

So the SSM security group is attached to all the nodes that were stood up by the RI. Is that to say I need to attach it to any nodes within that subnet if I want them to be able to hit SSM?

Depending on the module version of VPC you are using, using the latest one v0.3.1

module.vpc.ssm_endpoint.access_sg_id

would need to be added to the extra_security_group_ids
If you have other ec2 servers that require ssm access you would need to add it to them
If the node ins the managed or unmanged which ever you are using have security group access then
A public IP is not necessary to connect using SSM
aws ssm start-session --target instance-id from the cli or connect from the aws console should both workAre you getting an error message?
Does the ssm endpoint have any restrictive policies in place VPC->Endpoints->ssm endpoint Policy tabWhat version of the RI are you testing this with?