3 ms·
Without even having to dive into userdata or metadata, just (a) create the role for the ec2; (b) attach the trust and permission policies; (c) create an "instan
by colemorrison 10y ago
Without even having to dive into userdata or metadata, just (a) create the role for the ec2; (b) attach the trust and permission policies; (c) create an "instance profile"; (d) attach the instance profile to your target instances.
If via console, that gets done behind the scenes when attaching the role. But ya roles use the security token service behind the scenes which allow for temp creds vs. storing sensitive stuffs on the instances.