Review the IAM role association for the EC2 instance

Attach a least-privilege role through an instance profile when an EC2 workload needs AWS API access.

Description

For EC2 applications that call AWS APIs, temporary role credentials are easier to manage than long-lived keys stored on the server. CloudFormation IamInstanceProfile attaches an instance profile containing the role. An instance that does not need AWS API access does not need unnecessary permissions.

Potential impact

Without the required credential path, API calls may fail or applications may rely on long-lived keys. If a stored key is exposed, its permissions can be misused.

Remediation

Create a role with an EC2 trust policy and the minimum required permissions, and attach it through an instance profile. Confirm that the application uses role credentials before removing and revoking unnecessary long-lived keys.

Examples

Replace the AMI ID with an approved image in the actual Region. AppRole refers to a separately declared role with an EC2 trust policy and the required permissions; its definition is omitted.

Before

yaml
Resources:
  AppServer:
    Type: AWS::EC2::Instance
    Properties:
      InstanceType: t3.micro
      ImageId: ami-1234567890abcdef0

No instance profile is attached.

After

yaml
Resources:
  AppServer:
    Type: AWS::EC2::Instance
    Properties:
      InstanceType: t3.micro
      ImageId: ami-1234567890abcdef0
      IamInstanceProfile: !Ref AppInstanceProfile

  AppInstanceProfile:
    Type: AWS::IAM::InstanceProfile
    Properties:
      Roles:
        - !Ref AppRole

The profile attaches the role. Also verify the application’s credential source and effective API permissions.

References