Phase Verbs / Action Phrases
| Phrase | Meaning |
|---|---|
| assign (a role to) | attach an IAM role to an AWS service |
| perform actions on behalf of | do something in AWS using another entity’s identity |
| launch (an EC2 instance) | start a virtual server in AWS |
| grant (permissions to a service) | allow an AWS service to call AWS APIs |
Technical Vocabulary
| Term | Definition |
|---|---|
| IAM Role | An IAM identity (like a user) intended to be assumed by AWS services, not people |
| EC2 Instance | A virtual server in AWS; used as the main example of a service that needs a role |
| Lambda Function | Serverless compute service in AWS — another common role use case |
| CloudFormation | AWS service for provisioning infrastructure from templates — also uses a role |
| Assume a role | When an AWS service takes on the permissions defined in an IAM Role to make API calls |
Key Concepts
Why IAM Roles Exist
- AWS services like EC2, Lambda, CloudFormation need to make API calls to AWS
- They need permissions to do so — just like IAM users
- We solve this by creating an IAM Role and attaching it to the service
- The service then assumes that role and gets the permissions in its policies
IAM Role vs IAM User
| IAM User | IAM Role | |
|---|---|---|
| Used by | Real people | AWS services (or other accounts) |
| Authentication | Password + access keys | Temporary credentials (assumed) |
| Example | Developer logs in | EC2 instance calls S3 |
Common Role Use Cases
| Service | Role Use Case |
|---|---|
| EC2 | Read from S3, write logs to CloudWatch |
| Lambda | Process data from SQS, write results to DynamoDB |
| CloudFormation | Create/update/delete resources on your behalf |
Exam Tips
- IAM Roles are for AWS services, not people
- EC2 Role is the most common example — an EC2 instance needs a role to call other AWS services
- Roles use temporary credentials (not long-lived access keys)
- A role is attached at launch time (for EC2) or configured on the service