setting-up-ec2-instance-profiles
aws/agent-toolkit-for-aws
Securely grant EC2 instances AWS service access via IAM roles and instance profiles without hardcoded credentials.
What is setting-up-ec2-instance-profiles?
This skill configures EC2 instances to call AWS services securely using IAM roles and instance profiles with temporary credentials. Use it when you need to grant an EC2 instance permissions to access services like S3, DynamoDB, SQS, or CloudWatch without embedding access keys in your application.
- Create and attach IAM roles to EC2 instances via instance profiles
- Configure least-privilege policies for specific AWS service access
- Eliminate hardcoded credentials from EC2 applications
- Enable temporary credential rotation through the AWS credential chain
- Handle instance profile replacement and propagation
- Verify credential availability after attachment
How to install setting-up-ec2-instance-profiles
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill setting-up-ec2-instance-profiles- AWS CLI configured with appropriate credentials
- Access to create IAM roles and instance profiles
- An existing EC2 instance to attach the profile to
How to use setting-up-ec2-instance-profiles
- 1.Identify the AWS services and specific actions your EC2 instance needs to access
- 2.Create an IAM role with a trust policy allowing EC2 to assume it
- 3.Attach policies to the role granting least-privilege permissions for required actions
- 4.Create an instance profile and attach the IAM role to it
- 5.Attach the instance profile to your EC2 instance
- 6.Wait 30–60 seconds for propagation and verify credentials are available
- 7.Remove any hardcoded credentials from application config files and environment variables
Use cases
- Granting an EC2 web server permissions to read from an S3 bucket
- Allowing an EC2 application to write logs to CloudWatch
- Enabling an EC2 worker to consume messages from an SQS queue
- Providing DynamoDB access to an application running on EC2
- Replacing hardcoded AWS credentials in existing EC2 deployments
- AWS infrastructure engineers
- DevOps practitioners
- Application developers deploying to EC2
- Security-conscious teams implementing least-privilege access
setting-up-ec2-instance-profiles FAQ
Instance profile propagation typically takes 30–60 seconds. Applications may need to be restarted to pick up the new credentials.
Verify that the IAM role's policies include the required actions and resource ARNs, remove any hardcoded credentials from config files and environment variables, and check CloudTrail logs for specific access denied errors.
Yes, the procedure handles replacement and will prompt before disassociating the existing profile.
Instance profiles use temporary credentials that are automatically rotated by AWS, are more secure, and follow AWS best practices for least-privilege access without embedding secrets in your application.
After attachment and propagation, you can check credential availability by running AWS CLI commands or examining the instance metadata endpoint at http://169.254.169.254/latest/meta-data/iam/security-credentials/.
Full instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: setting-up-ec2-instance-profiles description: Configures EC2 instances to securely call AWS services by creating and attaching IAM roles via instance profiles, eliminating hardcoded credentials. Use when an EC2 instance needs permissions to access AWS services like S3, DynamoDB, SQS, or CloudWatch through temporary credentials. version: 1
Setting Up EC2 Instance Profiles
Overview
Domain expertise for granting EC2 instances secure access to AWS services using IAM roles and instance profiles. Covers the full lifecycle: identifying required permissions, creating or reusing IAM roles with least-privilege policies, creating instance profiles, attaching them to EC2 instances, and verifying credential availability.
Configure an EC2 instance profile
To set up an IAM role and instance profile for an EC2 instance, follow the procedure exactly. See EC2 instance profile setup procedure.
Troubleshooting
Instance not found
Verify the instance ID and region are correct. List instances with aws ec2 describe-instances --region <region>.
Instance already has a profile
The procedure handles replacement — it will prompt before disassociating the existing profile.
Credentials not available after attachment
Instance profile propagation can take 30–60 seconds. Applications may need a restart to pick up new credentials.
Access denied errors
Check that the role's policies include the required actions and resource ARNs. Review CloudTrail logs for the specific denied action.
Application still uses hardcoded credentials
Remove credentials from config files, environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY), and ~/.aws/credentials. The SDK default credential chain will then use the instance profile.
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

setup
Configure AWS DevOps and Security Agent connections for MCP integration.

setup-devops-agent
Setup and diagnostics for AWS DevOps Agent MCP connection in Claude.

setup-security-agent
Configure AWS Security Agent workspace with agent space, IAM role, and S3 bucket.

shieldadvanced
Configure AWS Shield Advanced for enhanced DDoS protection, automatic layer 7 mitigation, and expert support.

signing-in-to-aws
Get short-term AWS credentials for local development via `aws login` with auto-rotating 15-minute refresh.

sitetositevpn
Configure AWS Site-to-Site VPN connections between on-premises networks and AWS with routing, bandwidth, and high-availability options.