AWS SAA – Lecture 25: IAM Roles for AWS Services

Published on
Written by Henry Nguyen

Phase Verbs / Action Phrases

PhraseMeaning
assign (a role to)attach an IAM role to an AWS service
perform actions on behalf ofdo something in AWS using another entity’s identity
launch (an EC2 instance)start a virtual server in AWS
grant (permissions to a service)allow an AWS service to call AWS APIs

Technical Vocabulary

TermDefinition
IAM RoleAn IAM identity (like a user) intended to be assumed by AWS services, not people
EC2 InstanceA virtual server in AWS; used as the main example of a service that needs a role
Lambda FunctionServerless compute service in AWS — another common role use case
CloudFormationAWS service for provisioning infrastructure from templates — also uses a role
Assume a roleWhen an AWS service takes on the permissions defined in an IAM Role to make API calls

Key Concepts

Why IAM Roles Exist

  • AWS services like EC2, Lambda, CloudFormation need to make API calls to AWS
  • They need permissions to do so — just like IAM users
  • We solve this by creating an IAM Role and attaching it to the service
  • The service then assumes that role and gets the permissions in its policies

IAM Role vs IAM User

IAM UserIAM Role
Used byReal peopleAWS services (or other accounts)
AuthenticationPassword + access keysTemporary credentials (assumed)
ExampleDeveloper logs inEC2 instance calls S3

Common Role Use Cases

ServiceRole Use Case
EC2Read from S3, write logs to CloudWatch
LambdaProcess data from SQS, write results to DynamoDB
CloudFormationCreate/update/delete resources on your behalf

Exam Tips

  • IAM Roles are for AWS services, not people
  • EC2 Role is the most common example — an EC2 instance needs a role to call other AWS services
  • Roles use temporary credentials (not long-lived access keys)
  • A role is attached at launch time (for EC2) or configured on the service