Create IAM Role
Create IAM Role
We will proceed to create an IAM role for user EC2 Administrator along with the policies created in the previous section.
- Login to AWS Management Console and access IAM Management Console.
- In the left-hand navigation bar, select Roles and click the Create role button.
data:image/s3,"s3://crabby-images/c924f/c924f70b35011e5339c2d27722333289e87dd9a9" alt="IAM Role"
- In the new creation screen, we select Another AWS account and enter our account ID (you can find Account ID in My Account), besides Require MFA as a mandatory choice (best practice).
data:image/s3,"s3://crabby-images/5bab4/5bab4b8e0d653d5fac41e5132fdb1e158d22fb3c" alt="IAM Role"
In the Attach permissions policies area, we will choose the following policies in turn:
- ec2-list-read
- ec2-create-tags
- ec2-create-tags-existing
- ec2-run-instances
- ec2-manage-instances
data:image/s3,"s3://crabby-images/b75fb/b75fba0c58855fc30463a2731afdb777832304d0" alt="IAM Role"
- Select Next: Tags.
data:image/s3,"s3://crabby-images/4f97b/4f97bbc59d3a56c2c29db77e6385cc271364c233" alt="IAM Role"
- For automatic configuration. Select Next: Review to proceed with the review.
- Enter a name (eg ec2-admin-team-alpha) along with a specific description.
data:image/s3,"s3://crabby-images/b1ac3/b1ac35777c67260daa171b853fb455c4a8800f9d" alt="IAM Role"
- Proceed to create by clicking Create role.
data:image/s3,"s3://crabby-images/848bf/848bf85faf0ea14e4ae1b0a66428f8722f050555" alt="IAM Role"
-
After successful creation, in the list of IAM roles, we choose ec2-admin-team-alpha and need to save 2 things:
data:image/s3,"s3://crabby-images/5e755/5e755fe86e32a0874b425e7c34354e0c7496d4cc" alt="IAM Role"
- Use ARN IAM user to configure Trust relationships
data:image/s3,"s3://crabby-images/ff54e/ff54e2f15ba84ac8387839e9bfdab8b7247faec8" alt="IAM Role"
- Make an edit trust policy
data:image/s3,"s3://crabby-images/aaad4/aaad459055ec0f5343265fd7895ea0e268745d8d" alt="IAM Role"
- Complete the update.
data:image/s3,"s3://crabby-images/65270/652701ee431fa43324abfddb4e9b9836711d611d" alt="IAM Role"