setting-up-ec2-instance-profiles

par aws

Configures EC2 instances to securely call AWS services by creating and attaching IAM roles via instance profiles, eliminating hardcoded credentials. Use when…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill setting-up-ec2-instance-profiles

Setting Up EC2 Instance Profiles

Overview

Domain expertise for granting EC2 instances secure access to AWS services using IAM roles and instance profiles. Covers the full lifecycle: identifying required permissions, creating or reusing IAM roles with least-privilege policies, creating instance profiles, attaching them to EC2 instances, and verifying credential availability.

Configure an EC2 instance profile

To set up an IAM role and instance profile for an EC2 instance, follow the procedure exactly. See EC2 instance profile setup procedure.

Troubleshooting

Instance not found

Verify the instance ID and region are correct. List instances with aws ec2 describe-instances --region <region>.

Instance already has a profile

The procedure handles replacement — it will prompt before disassociating the existing profile.

Credentials not available after attachment

Instance profile propagation can take 30–60 seconds. Applications may need a restart to pick up new credentials.

Access denied errors

Check that the role's policies include the required actions and resource ARNs. Review CloudTrail logs for the specific denied action.

Application still uses hardcoded credentials

Remove credentials from config files, environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY), and ~/.aws/credentials. The SDK default credential chain will then use the instance profile.

Plus de skills de aws

agents-build
aws
Use to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource…
official
agents-connect
aws
À utiliser lors de la connexion de votre agent à des API, outils ou services externes via Gateway, ou pour restreindre l'accès aux outils avec des politiques Cedar. Gère la configuration de la passerelle, la cible…
official
agents-debug
aws
Use when your agent or environment is broken — wrong answers, errors, timeouts, tool failures, or CLI issues. Reads traces and logs to diagnose root causes.…
official
agents-deploy
aws
À utiliser lors du déploiement de votre agent sur AWS, ou lorsqu'un déploiement a échoué. Gère la validation pré-vol, le diagnostic des erreurs CDK/IAM/quota, la gestion des versions, le rollback,…
official
agents-get-started
aws
À utiliser lorsqu'un développeur souhaite créer un nouveau projet d'agent ou démarrer avec AgentCore. Gère la sélection du framework, le scaffolding du projet, le premier déploiement, et…
official
agents-harden
aws
À utiliser lors de la préparation de votre agent pour la production — cadrage IAM, authentification entrante (JWT, SigV4), gestion des secrets, optimisation du démarrage à froid, cycle de vie des sessions, taux…
official
agents-pay
aws
Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying…
official
amazon-aurora-mysql
aws
Amazon Aurora MySQL — creates, modifies, and advises on Aurora MySQL clusters specifically (MySQL-compatible engine, Aurora serverless, parallel query).…
official