---
title: "Patching Scheduled Auto Scaling Groups with AWS"
description: "This blog post explores strategies for effectively applying security patches and updates to AWS Auto Scaling Groups (ASGs) that rely on scheduled scaling actions. It highlights the challenges of coord"
doc_version: 1.0.0
last_updated: 2026-05-09
date_published: 2025-01-17
canonical: https://ccx.hu/blog/patching-scheduled-auto-scaling-groups-with-aws
---

# Patching Scheduled Auto Scaling Groups with AWS

> This blog post explores strategies for effectively applying security patches and updates to AWS Auto Scaling Groups (ASGs) that rely on scheduled scaling actions. It highlights the challenges of coordinating instance refreshes with automated capacity changes and outlines best practices to ensure instances remain secure without disrupting predefined availability windows.

<h2>Introduction</h2>
<p>Maintaining up-to-date patches on Amazon EC2 instances is critical for security and compliance. However, patching auto-scaling groups (ASGs) can be challenging, especially when dealing with scheduled ASGs that are scaled down during maintenance windows. Traditional patching jobs rely on running instances, creating a gap when instances are unavailable.</p>
<p>In this post, we address this issue by exploring how to automate the patching process for scheduled ASGs. We’ll leverage AWS Systems Manager (SSM) Maintenance Windows, CloudFormation, and EventBridge to create a solution that ensures patches are applied even when no instances are running at the time of the maintenance job.</p>

<h2>Problem Statement</h2>
<p>Organizations often use scheduled ASGs to optimize costs by scaling down during non-peak hours or maintenance windows. However, this introduces several challenges when it comes to patching:</p>
<ul>
  <li><strong>No Running Instances:</strong> Since the ASG scales down to zero, there are no instances to trigger the patching process.</li>
  <li><strong>Delayed Compliance:</strong> Patching jobs remain pending until instances are scaled up manually, leading to security and compliance gaps.</li>
  <li><strong>Increased Manual Intervention:</strong> Administrators may need to manually scale up instances to execute patches, adding operational overhead.</li>
</ul>
<p>Without a tailored solution, these gaps can leave critical systems exposed to vulnerabilities.</p>

<h2>Reference to Existing Solutions</h2>
<p>In a previous blog, <a href="https://dev.to/aws-builders/patching-your-auto-scaling-group-on-aws-42b0" target="_blank">Patching Your Auto Scaling Group on AWS</a>, I discussed how to patch standard ASGs effectively. That solution focused on ensuring that patching was streamlined for running instances in dynamically scaled environments. However, scheduled ASGs introduce unique challenges due to their scaled-down state during maintenance windows.</p>
<p>This blog builds on that foundation, offering a targeted solution to patch scheduled ASGs by automating scaling, patch application, and scaling back down—ensuring seamless compliance without manual intervention.</p>
<h2>AWS Automation for Scheduled Auto Scaling Groups</h2>
<p>Patching scheduled auto-scaling groups requires an automation strategy that accounts for their scaled-down state during maintenance windows. AWS provides several tools that make this possible:</p>
<ul>
  <li><strong>AWS Systems Manager (SSM) Maintenance Windows:</strong> Automates patching during predefined schedules.</li>
  <li><strong>Amazon EventBridge:</strong> Coordinates events and triggers necessary actions to manage scaling and patching processes.</li>
  <li><strong>IAM Roles and Policies:</strong> Grants permissions required for automation tasks like scaling, patching, and updating ASG configurations.</li>
</ul>
<p>By combining these services, you can automate scaling up instances for patching, applying patches, and scaling back down—all without manual intervention.</p>

<h2>Implementation Strategy</h2>
<h3>Step 1: Identify Scheduled Auto Scaling Groups</h3>
<p>Tagging plays a critical role in identifying ASGs that require patching. Use tags like <code>ep:asg:patch=true</code> to specify the groups to be included in the automation process.</p>

<h3>Step 2: Schedule and Automate the Patching Process</h3>
<p>Leverage SSM Maintenance Windows to define patching schedules using cron expressions. For instance, you can create a window to run every second Wednesday at 4:00 AM:</p>
<pre><code>
Schedule: cron(0 4 ? * WED#2 *)
</code></pre>

<h3>Step 3: Scale Up Instances During Maintenance</h3>
<p>The automation logic temporarily scales up the ASG to ensure there are running instances for patching. This scaling is coordinated through EventBridge and Lambda functions.</p>

<h3>Step 4: Apply Patches and Scale Down</h3>
<p>Once patches are applied, the automation script scales the ASG back to its original size, maintaining cost-efficiency while ensuring compliance.</p>

<h2>Code Walkthrough</h2>
<p>The provided CloudFormation (CFN) template is designed to automate this entire process. Below are some key snippets to demonstrate how the solution works:</p>

<h3>Tagging ASGs for Patching</h3>
<p>The template uses tags to identify ASGs that require patching. The following parameters define the tag key and value:</p>
<pre><code>
Parameters:
  AsgTagKey:
    Type: String
    Default: ep:asg:patch
  AsgTagValue:
    Type: String
    Default: "true"
</code></pre>
<p>This ensures that only tagged ASGs are included in the patching process.</p>

<h3>Scheduling Maintenance Windows</h3>
<p>The template creates SSM Maintenance Windows based on environment and month-specific schedules:</p>
<pre><code>
Resources:
  MaintenanceWindow:
    Type: 'AWS::SSM::MaintenanceWindow'
    Properties:
      AllowUnassociatedTargets: false
      Cutoff: 0
      Duration: 1
      Name: !Sub "Maintenance_Window-${AsgTagValue}"
      Schedule: cron(0 4 ? * WED#2 *)
      Description: !Sub "Maintenance window for patching ${AsgTagValue} ASGs"
</code></pre>

<h3>Scaling Logic</h3>
<p>The automation script checks the ASG's desired capacity and scales up instances if the ASG is scaled down:</p>
<pre><code>
def scaleUpASG(asg_client, asg_name):
    asg_client.update_auto_scaling_group(
        AutoScalingGroupName=asg_name,
        MinSize=1,
        DesiredCapacity=1
    )
</code></pre>
<p>This function ensures there are running instances available for patching.</p>

<h3>Patching and Creating a New AMI</h3>
<p>The automation script applies patches to instances and creates a new AMI for the ASG:</p>
<pre><code>
def createAMI(ec2_client, instance_id, new_ami_name):
    ec2_client.create_image(
        InstanceId=instance_id,
        Name=new_ami_name,
        Description="Patched AMI created for ASG",
        NoReboot=True
    )
</code></pre>
<p>This ensures that patched AMIs are used for subsequent instance launches, maintaining compliance.</p>

<h3>Updating the Auto Scaling Group</h3>
<p>Once the patched AMI is created, the ASG is updated to use the new AMI:</p>
<pre><code>
def updateASG(asg_client, asg_name, launch_template_id, new_version):
    asg_client.update_auto_scaling_group(
        AutoScalingGroupName=asg_name,
        LaunchTemplate={
            'LaunchTemplateId': launch_template_id,
            'Version': str(new_version)
        }
    )
</code></pre>
<p>The new launch template version ensures that all future instances in the ASG are launched with the patched AMI.</p>

<h3>Scaling Down After Patching</h3>
<p>Finally, the ASG is scaled back to its original size:</p>
<pre><code>
def scaleDownASG(asg_client, asg_name, original_min, original_desired):
    asg_client.update_auto_scaling_group(
        AutoScalingGroupName=asg_name,
        MinSize=original_min,
        DesiredCapacity=original_desired
    )
</code></pre>
<p>This step restores the ASG to its cost-efficient state while ensuring patches have been applied.</p>

<h2>Best Practices</h2>
<h3>1. Use Consistent Tagging</h3>
<p>Ensure that all ASGs requiring patching are tagged consistently. This simplifies the automation process and minimizes the risk of missing critical groups.</p>

<h3>2. Test Automation in Non-Production Environments</h3>
<p>Before deploying automation scripts in production, test them in non-production environments to validate cron schedules, scaling logic, and patch application processes.</p>

<h3>3. Monitor Maintenance Windows</h3>
<p>Integrate monitoring tools like Amazon SNS to receive notifications about the status of maintenance windows. This allows administrators to track successes, failures, and potential issues.</p>

<h3>4. Audit and Review Launch Templates</h3>
<p>Regularly review and update ASG launch templates to ensure they reference the latest AMIs with applied patches.</p>

<h3>5. Plan for Compliance</h3>
<p>Align patching strategies with organizational and regulatory compliance requirements to avoid penalties and enhance security.</p>

<h2>Conclusion</h2>
<p>Patching scheduled auto-scaling groups can be a complex task due to their scaled-down state during maintenance windows. By leveraging AWS Systems Manager, CloudFormation, and EventBridge, this blog demonstrates how to automate the entire process—from scaling up instances to applying patches and scaling back down.</p>
<p>This solution addresses security and compliance gaps without increasing operational overhead, ensuring that your ASGs remain secure and cost-efficient. If you’ve faced similar challenges, consider implementing this automation strategy to streamline your patching workflows.</p>
<p>Feel free to share your thoughts or questions in the comments below!</p>

---

## Sitemap

- [Read this post on the web](https://ccx.hu/blog/patching-scheduled-auto-scaling-groups-with-aws)
- [All blog posts](https://ccx.hu/blog)
- [Full site map](https://ccx.hu/sitemap.md)
- [Home](https://ccx.hu/)
- [Services](https://ccx.hu/services)
- [EU AI Act Compliance](https://ccx.hu/eu-ai-act)
- [AWS GenAI Production Readiness](https://ccx.hu/aws-genai-review)
- [Glossary](https://ccx.hu/glossary)
- [Contact](https://ccx.hu/contact)
