SSH by IAM role, patching by query, not by hand.
One binding change replaces a per-instance metadata edit repeated across a fleet.
Patch Management
Scheduled fleet-wide patching + compliance reporting
OS Config Agent
Runs on every instance, powers the other two tools
OS Policy Assignment
Continuously-enforced baseline configuration
OS Login also propagates consistent Linux POSIX account details (UID/GID) from Cloud Identity across every enabled instance — useful anywhere file ownership needs to be consistent fleet-wide.