Description
For EC2 applications that call AWS APIs, temporary role credentials are easier to manage than long-lived keys stored on the server. CloudFormation IamInstanceProfile attaches an instance profile containing the role. An instance that does not need AWS API access does not need unnecessary permissions.
Potential impact
Without the required credential path, API calls may fail or applications may rely on long-lived keys. If a stored key is exposed, its permissions can be misused.
Remediation
Create a role with an EC2 trust policy and the minimum required permissions, and attach it through an instance profile. Confirm that the application uses role credentials before removing and revoking unnecessary long-lived keys.
Examples
Replace the AMI ID with an approved image in the actual Region. AppRole refers to a separately declared role with an EC2 trust policy and the required permissions; its definition is omitted.
Before
Resources:
AppServer:
Type: AWS::EC2::Instance
Properties:
InstanceType: t3.micro
ImageId: ami-1234567890abcdef0
No instance profile is attached.
After
Resources:
AppServer:
Type: AWS::EC2::Instance
Properties:
InstanceType: t3.micro
ImageId: ami-1234567890abcdef0
IamInstanceProfile: !Ref AppInstanceProfile
AppInstanceProfile:
Type: AWS::IAM::InstanceProfile
Properties:
Roles:
- !Ref AppRole
The profile attaches the role. Also verify the application’s credential source and effective API permissions.