Create the server's IAM role
Give the EC2 instance an identity so you can open a shell with Session Manager and no SSH keys.
About 8 min · Verified 8 October 2026
The API server will live in a private subnet with no public IP. You will still need a shell on it. AWS Systems Manager Session Manager provides one over HTTPS, with no SSH keys, no open port 22 and a log of who connected. For that to work, the instance needs an IAM role that allows the Systems Manager agent to talk to AWS.
An instance profile is the wrapper that attaches a role to an EC2 instance. When you create a role for EC2 in the console, AWS creates a matching instance profile with the same name automatically.
Create the role#
Start the role wizard#
Open IAMRolesCreate role.
| Field | Value |
|---|---|
| Trusted entity type | AWS service |
| Service or use case | EC2 |
| Use case | EC2 (the first option, "Allows EC2 instances to call AWS services on your behalf") |
Choose Next.
Attach the Systems Manager policy#
In the search box type AmazonSSMManagedInstanceCore and tick that managed policy. Choose Next.
Name it and create#
| Field | Value |
|---|---|
| Role name | shortlink-ec2-role |
| Description | Lets the ShortLink API server use Systems Manager |
Review that the Trust policy shows ec2.amazonaws.com and Permissions lists AmazonSSMManagedInstanceCore, then choose Create role.
Verify the instance profile exists#
aws iam get-role --role-name shortlink-ec2-role --query 'Role.{name:RoleName,arn:Arn}' --output table
aws iam get-instance-profile --instance-profile-name shortlink-ec2-role \
--query 'InstanceProfile.{profile:InstanceProfileName,role:Roles[0].RoleName}' --output tableshortlink-ec2-role contains the role shortlink-ec2-role.get-instance-profile says NoSuchEntity
That happens if the role was created with the CLI or another tool, which does not create the profile for you. Create it manually:
aws iam create-instance-profile --instance-profile-name shortlink-ec2-role
aws iam add-role-to-instance-profile --instance-profile-name shortlink-ec2-role --role-name shortlink-ec2-roleNext: S3 website bucket and the load balancer come before the server.
Found a mistake? Edit this page on GitHub.