Skip to content

Create the server's IAM role

Give the EC2 instance an identity so you can open a shell with Session Manager and no SSH keys.

About 8 min · Verified 8 October 2026

0 of 4 steps done0%

The API server will live in a private subnet with no public IP. You will still need a shell on it. AWS Systems Manager Session Manager provides one over HTTPS, with no SSH keys, no open port 22 and a log of who connected. For that to work, the instance needs an IAM role that allows the Systems Manager agent to talk to AWS.

An instance profile is the wrapper that attaches a role to an EC2 instance. When you create a role for EC2 in the console, AWS creates a matching instance profile with the same name automatically.

Create the role#

Start the role wizard#

Open IAMRolesCreate role.

FieldValue
Trusted entity typeAWS service
Service or use caseEC2
Use caseEC2 (the first option, "Allows EC2 instances to call AWS services on your behalf")

Choose Next.

Attach the Systems Manager policy#

In the search box type AmazonSSMManagedInstanceCore and tick that managed policy. Choose Next.

Name it and create#

FieldValue
Role nameshortlink-ec2-role
DescriptionLets the ShortLink API server use Systems Manager

Review that the Trust policy shows ec2.amazonaws.com and Permissions lists AmazonSSMManagedInstanceCore, then choose Create role.

Verify the instance profile exists#

Your computerCheck role and instance profile
aws iam get-role --role-name shortlink-ec2-role --query 'Role.{name:RoleName,arn:Arn}' --output table
aws iam get-instance-profile --instance-profile-name shortlink-ec2-role \
  --query 'InstanceProfile.{profile:InstanceProfileName,role:Roles[0].RoleName}' --output table
You should see
Both commands succeed, and the instance profile shortlink-ec2-role contains the role shortlink-ec2-role.
get-instance-profile says NoSuchEntity

That happens if the role was created with the CLI or another tool, which does not create the profile for you. Create it manually:

Your computerCreate the instance profile by hand
aws iam create-instance-profile --instance-profile-name shortlink-ec2-role
aws iam add-role-to-instance-profile --instance-profile-name shortlink-ec2-role --role-name shortlink-ec2-role

Next: S3 website bucket and the load balancer come before the server.

Found a mistake? Edit this page on GitHub.