PluginBench
Skill
Official
Pass
Audit score 90

setting-up-ec2-instance-profiles

aws/agent-toolkit-for-aws

Securely grant EC2 instances AWS service access via IAM roles and instance profiles without hardcoded credentials.

What is setting-up-ec2-instance-profiles?

This skill configures EC2 instances to call AWS services securely using IAM roles and instance profiles with temporary credentials. Use it when you need to grant an EC2 instance permissions to access services like S3, DynamoDB, SQS, or CloudWatch without embedding access keys in your application.

  • Create and attach IAM roles to EC2 instances via instance profiles
  • Configure least-privilege policies for specific AWS service access
  • Eliminate hardcoded credentials from EC2 applications
  • Enable temporary credential rotation through the AWS credential chain
  • Handle instance profile replacement and propagation
  • Verify credential availability after attachment

How to install setting-up-ec2-instance-profiles

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill setting-up-ec2-instance-profiles
Prerequisites
  • AWS CLI configured with appropriate credentials
  • Access to create IAM roles and instance profiles
  • An existing EC2 instance to attach the profile to
Claude Code
Cursor
Windsurf
Cline

How to use setting-up-ec2-instance-profiles

  1. 1.Identify the AWS services and specific actions your EC2 instance needs to access
  2. 2.Create an IAM role with a trust policy allowing EC2 to assume it
  3. 3.Attach policies to the role granting least-privilege permissions for required actions
  4. 4.Create an instance profile and attach the IAM role to it
  5. 5.Attach the instance profile to your EC2 instance
  6. 6.Wait 30–60 seconds for propagation and verify credentials are available
  7. 7.Remove any hardcoded credentials from application config files and environment variables

Use cases

Good for
  • Granting an EC2 web server permissions to read from an S3 bucket
  • Allowing an EC2 application to write logs to CloudWatch
  • Enabling an EC2 worker to consume messages from an SQS queue
  • Providing DynamoDB access to an application running on EC2
  • Replacing hardcoded AWS credentials in existing EC2 deployments
Who it's for
  • AWS infrastructure engineers
  • DevOps practitioners
  • Application developers deploying to EC2
  • Security-conscious teams implementing least-privilege access

setting-up-ec2-instance-profiles FAQ

How long does it take for an instance profile to become available after attachment?

Instance profile propagation typically takes 30–60 seconds. Applications may need to be restarted to pick up the new credentials.

What should I do if my application still can't access AWS services after attaching the profile?

Verify that the IAM role's policies include the required actions and resource ARNs, remove any hardcoded credentials from config files and environment variables, and check CloudTrail logs for specific access denied errors.

Can I replace an existing instance profile on a running instance?

Yes, the procedure handles replacement and will prompt before disassociating the existing profile.

Why should I use instance profiles instead of hardcoded credentials?

Instance profiles use temporary credentials that are automatically rotated by AWS, are more secure, and follow AWS best practices for least-privilege access without embedding secrets in your application.

How do I verify that credentials are available on the instance?

After attachment and propagation, you can check credential availability by running AWS CLI commands or examining the instance metadata endpoint at http://169.254.169.254/latest/meta-data/iam/security-credentials/.

Full instructions (SKILL.md)

Source of truth, from aws/agent-toolkit-for-aws.


name: setting-up-ec2-instance-profiles description: Configures EC2 instances to securely call AWS services by creating and attaching IAM roles via instance profiles, eliminating hardcoded credentials. Use when an EC2 instance needs permissions to access AWS services like S3, DynamoDB, SQS, or CloudWatch through temporary credentials. version: 1

Setting Up EC2 Instance Profiles

Overview

Domain expertise for granting EC2 instances secure access to AWS services using IAM roles and instance profiles. Covers the full lifecycle: identifying required permissions, creating or reusing IAM roles with least-privilege policies, creating instance profiles, attaching them to EC2 instances, and verifying credential availability.

Configure an EC2 instance profile

To set up an IAM role and instance profile for an EC2 instance, follow the procedure exactly. See EC2 instance profile setup procedure.

Troubleshooting

Instance not found

Verify the instance ID and region are correct. List instances with aws ec2 describe-instances --region <region>.

Instance already has a profile

The procedure handles replacement — it will prompt before disassociating the existing profile.

Credentials not available after attachment

Instance profile propagation can take 30–60 seconds. Applications may need a restart to pick up new credentials.

Access denied errors

Check that the role's policies include the required actions and resource ARNs. Review CloudTrail logs for the specific denied action.

Application still uses hardcoded credentials

Remove credentials from config files, environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY), and ~/.aws/credentials. The SDK default credential chain will then use the instance profile.