Least Privilege
Least Privilege
Create Groups
Create Groups
Secret Access Key
Do not use just one access key
Do not use just one access key
You can use the AWS CLI on your local laptop
Obtaining Command Line Tools on Laptop
Download / Install Python: https://www.python.org/downloads/
$ which python
$ ls -al /usr/bin/python
$ curl -O https://bootstrap.pypa.io/get-pip.py
$ python3 get-pip.py –user
$ pip –version
pip 9.0.1 from /Library/Python/2.7/site-packages/pip-9.0.1-py2.7.egg (python 2.7)
$ pip3 install awscli
$ aws –version
aws-cli/1.14.32 Python/3.6.4 Darwin/17.4.0 botocore/1.8.36
Configure Laptop to Use Access Key ID and Secret Access Key
$ aws configure
User: User Access Key ID: AKIAJRZM5PW6RABWXK5A
Pass: Secret Access Key: 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
Default Region: us-east-1
SSH to EC2 Instance
$ cd ‘/Users/mmarkl00/Google Drive/ssh-aws-2019’
$ ls -l
$ ssh ec2-user@3.85.20.192 -i MyEC2keyPair-2019.pem
$ sudo su -
aws configure
User: User Access Key ID: AKIAJRZM5PW6RABWXK5A
Pass: Secret Access Key: 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
Default Region: us-east-1
Risks of Storing Credentials on EC2 Instance
Risks of Storing Credentials on EC2 Instance