How to Attach an IAM Role to an EC2 Instance (No Access Keys)
To attach an IAM role to an EC2 instance, create a role in IAM with trusted entity AWS service → EC2 and only the permissions the instance needs, then in the EC2 console select the instance → Actions → Security → Modify IAM role → choose the role → Update IAM role. The AWS CLI and SDKs on the instance then get temporary credentials automatically, with no access keys stored on the server. Check it with aws sts get-caller-identity.
Friends, running aws configure on EC2 and typing in your own access key is the biggest mistake students make. If the server is compromised, the attacker gets your whole account. The fix: an IAM role. Example: your web server puts its backup into an S3 bucket every night – without using a single key. Let's create the role and attach it.
मित्रांनो, EC2 वर aws configure करून स्वतःची access key टाकणं – ही स्टुडंट्सची सर्वात मोठी चूक आहे. सर्व्हर compromise झाला की अटॅकर ला तुमचं पूर्ण अकाउंट मिळतं. यावर उपाय: IAM role. उदाहरण: तुमचा वेब सर्व्हर रोज रात्री बॅकअप S3 bucket मध्ये ठेवतो – एकही key न वापरता. चला, role बनवून अटॅच करूया.
दोस्तों, EC2 पर aws configure करके अपनी access key डालना – ये स्टूडेंट्स की सबसे बड़ी गलती है. सर्वर compromise हुआ तो अटैकर को आपका पूरा अकाउंट मिल जाता है. इसका उपाय: IAM role. उदाहरण: आपका वेब सर्वर रोज़ रात बैकअप S3 bucket में रखता है – एक भी key इस्तेमाल किए बिना. चलो, role बनाकर अटैच करते हैं.
Quick answer
Console: IAM → Roles → Create role → AWS service → EC2 → attach a policy (e.g. read access to one S3 bucket) → name web-s3-role → Create role. Then EC2 → select the instance → Actions → Security → Modify IAM role → web-s3-role → Update IAM role. Verify on the instance:
aws sts get-caller-identity # Arn: ...:assumed-role/web-s3-role/i-0123...
aws configure list # credential type: iam-role
aws s3 ls s3://my-site-backups/
AWS CLI to attach: aws ec2 associate-iam-instance-profile --instance-id i-0123456789abcdef0 --iam-instance-profile Name=web-s3-role
What do I need before attaching an IAM role?
- An EC2 instance with SSH access — see How to Launch an EC2 Instance and How to SSH into EC2. Amazon Linux 2023 comes with the AWS CLI installed.
- An AWS user that may create IAM roles and change EC2 instances (for example an administrator in your own lab account).
- A clear idea of what the server must do, for example "upload backups to the bucket
my-site-backups". That decides the policy.
How does an IAM role give EC2 its credentials?
With an IAM role attached, the AWS CLI gets temporary credentials from the instance metadata service and calls Amazon S3 with them. AWS rotates them automatically, and no access keys are stored on the server.
IAM role अटॅच असला की AWS CLI instance metadata service कडून temporary credentials घेतो आणि त्यांनी Amazon S3 ला कॉल करतो. AWS ते आपोआप बदलतो, आणि सर्व्हर वर एकही access key सेव्ह नसते.
IAM role अटैच हो तो AWS CLI instance metadata service से temporary credentials लेता है और उनसे Amazon S3 को कॉल करता है. AWS उन्हें अपने आप बदलता है, और सर्वर पर कोई access key सेव नहीं होती.
An IAM role is an identity with permissions but no long-term password or keys. When a role is attached to an instance (through an instance profile, which the console creates for you with the same name), AWS delivers temporary credentials to the instance through the instance metadata service at 169.254.169.254, and rotates them automatically. The AWS CLI and SDKs find them by themselves — your code needs no keys at all.
How do I attach an IAM role to an EC2 instance?
Step 1 — Create the role for EC2
IAM → Roles → Create role → Trusted entity type: AWS service → Use case: EC2 → Next.
Step 2 — Give it only the permissions it needs
Search for and tick a policy. For a quick test, AmazonS3ReadOnlyAccess works. For a real server, create your own policy that allows only the actions and the bucket it needs, for example:
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": ["s3:PutObject", "s3:GetObject"],
"Resource": "arn:aws:s3:::my-site-backups/*"
}]
}
Never attach AdministratorAccess to an application server: one bug in your code would hand an attacker the whole account.
Step 3 — Name and create the role
Role name: web-s3-role → check the trusted entity shows ec2.amazonaws.com → Create role.
Step 4 — Attach the role to the instance
EC2 → Instances → select the instance → Actions → Security → Modify IAM role → choose web-s3-role → Update IAM role. The instance keeps running; no stop or reboot is needed. For a new instance, pick the role at launch under Advanced details → IAM instance profile.
Step 5 — Verify on the instance
aws sts get-caller-identity
aws configure list
aws s3 ls s3://my-site-backups/ # read test (bucket name = yours)
echo test > t.txt && aws s3 cp t.txt s3://my-site-backups/t.txt # write test (needs s3:PutObject)
get-caller-identity shows an ARN with assumed-role/web-s3-role/..., and aws configure list shows the type iam-role. The server now talks to AWS with no keys on disk! 🎉
Ravindra Bagale's Tip
Students create the role but forget to attach it to the EC2 instance – then the CLI says "Unable to locate credentials" and they rush to paste an access key into the code. Never! First run aws sts get-caller-identity: if the role doesn't show, do Actions → Security → Modify IAM role. Role = no keys, remember that.
Ravindra Bagale's Tip – मराठी
Role बनवला पण EC2 ला अटॅच करायला विसरले – मग CLI "Unable to locate credentials" देतो आणि स्टुडंट्स घाईघाईत कोड मध्ये access key टाकतात. कधीच नाही! आधी aws sts get-caller-identity चालवा: role दिसला नाही तर Actions → Security → Modify IAM role करा. Role = no keys, हे लक्षात ठेवा.
Ravindra Bagale's Tip – हिंदी
Role बनाया पर EC2 से अटैच करना भूल गए – फिर CLI "Unable to locate credentials" देता है और स्टूडेंट्स जल्दी-जल्दी कोड में access key डाल देते हैं. कभी नहीं! पहले aws sts get-caller-identity चलाओ: role नहीं दिखा तो Actions → Security → Modify IAM role करो. Role = no keys, ये याद रखो.
How can I see the role credentials on the instance?
The metadata service shows the attached role. New instances require IMDSv2, which needs a token first:
TOKEN=$(curl -s -X PUT http://169.254.169.254/latest/api/token -H "X-aws-ec2-metadata-token-ttl-seconds: 60")
curl -s -H "X-aws-ec2-metadata-token: $TOKEN" http://169.254.169.254/latest/meta-data/iam/security-credentials/; echo
The output is the role name. You never copy these credentials anywhere — the CLI and SDKs read and refresh them for you. Keep IMDSv2 required: a plain request without a token cannot read them, which protects the role credentials from simple server-side request forgery (SSRF) bugs.
Ravindra Bagale's Tip
💡 If the CLI still uses an old access key after you attach the role, old keys are still sitting in ~/.aws/credentials. The CLI checks environment variables and config files first, and the role only after that. aws configure list should show the type iam-role. Remove the old file and deactivate that key in IAM. Don't forget!
Ravindra Bagale's Tip – मराठी
💡 Role अटॅच केला तरी CLI जुनी access key वापरत असेल, तर ~/.aws/credentials मध्ये जुन्या keys अजून आहेत. CLI आधी environment variables आणि config फाइल्स बघतो, आणि मग role. aws configure list मध्ये टाइप iam-role दिसला पाहिजे. जुनी फाइल काढा, आणि ती key IAM मधून deactivate करा. अजिबात विसरू नका!
Ravindra Bagale's Tip – हिंदी
💡 Role अटैच करने के बाद भी CLI पुरानी access key इस्तेमाल कर रहा है, तो ~/.aws/credentials में पुरानी keys अभी भी पड़ी हैं. CLI पहले environment variables और config फ़ाइलें देखता है, और role बाद में. aws configure list में टाइप iam-role दिखना चाहिए. पुरानी फ़ाइल हटाओ और वो key IAM से deactivate करो. बिल्कुल मत भूलना!
How do I fix common IAM role errors on EC2?
Ghabru naka 😅 — read the exact message:
| Symptom | Likely cause | Fix |
|---|---|---|
Unable to locate credentials |
No role attached | Actions → Security → Modify IAM role; then aws sts get-caller-identity |
AccessDenied / not authorized to perform |
Role attached but policy does not allow the action or resource | Add the exact action (e.g. s3:PutObject) and bucket ARN to the role's policy |
| CLI still uses an old user | Keys in ~/.aws/credentials or environment variables |
aws configure list; remove the file/variables; deactivate the old key |
| Role not in the Modify IAM role list | Role was created for another service | Recreate it with trusted entity EC2 |
aws s3 ls works, upload fails |
Read-only policy | Grant s3:PutObject on arn:aws:s3:::bucket/* |
Metadata curl returns 401 Unauthorized |
IMDSv2 requires a token | Use the token commands above (this is good security) |
aws: command not found |
CLI not installed (non-Amazon Linux AMI) | Install AWS CLI v2 from the official AWS instructions |
Learn it properly
This guide is the short path. The free courses explain every step in depth, with labs:
- What is EC2: key concepts (IAM role / instance profile)
- EC2 best practices
- IAM done right (Cyber Security course)
- Encryption, logging, IAM roles and the S3 checklist (Cyber Security course)
- AWS setup: S3 bucket, IAM role and RDS (Cyber Security live project)
- EC2 metadata, SSRF and a leaked-key incident (Cyber Security course)
Got it? Create the role, give only the permissions you need, attach it with Modify IAM role, and confirm with aws sts get-caller-identity. Not a single access key on the server – that's the company standard.
समजलं का? Role बनवा, फक्त लागणाऱ्या permissions द्या, Modify IAM role ने अटॅच करा, आणि aws sts get-caller-identity ने confirm करा. सर्व्हर वर एकही access key नको – हाच कंपनी स्टँडर्ड आहे.
समझ आया? Role बनाओ, सिर्फ़ ज़रूरी permissions दो, Modify IAM role से अटैच करो, और aws sts get-caller-identity से confirm करो. सर्वर पर एक भी access key नहीं – यही कंपनी स्टैंडर्ड है.
Frequently asked questions
How do I attach an IAM role to a running EC2 instance?
Select the instance in the EC2 console, then Actions → Security → Modify IAM role, choose the role and click Update IAM role. No stop or reboot is needed.
Why use an IAM role instead of access keys on EC2?
A role gives short-lived credentials that AWS rotates automatically, and they never sit in a file you might leak. Long-lived access keys in code or ~/.aws/credentials are one of the most common ways cloud accounts get stolen.
How do I check that my instance is using the role?
Run aws sts get-caller-identity on the instance. The ARN should contain assumed-role/ and your role name. aws configure list shows iam-role as the credential type.
What is an instance profile?
The container that passes an IAM role to an EC2 instance. When you create a role for EC2 in the console, an instance profile with the same name is created automatically, so you just pick the role name.
Can one EC2 instance have two IAM roles?
No. An instance has one instance profile with one role at a time. Put all the permissions the instance needs into that role, or replace the role with Modify IAM role.
Why do I get "Unable to locate credentials" or AccessDenied?
Unable to locate credentials: no role is attached (or the CLI cannot reach the metadata service). AccessDenied: the role is attached but its policy does not allow that action or resource.