AWS AWSEC2: Clarified IAM policy usage in EC2 Instance Connect tutorial
Summary
Rephrased sentences about permissive IAM policies and AMI selection for instructional consistency.
Security assessment
Wording changes emphasize tutorial context but maintain existing security recommendations for least-privilege IAM policies.
Evidence
+This tutorial uses this highly permissive policy to keep the tutorial simple and focused on the specific configurations that this tutorial is teaching.
Diff
diff --git a/AWSEC2/latest/UserGuide/ec2-instance-connect-tutorial.md b/AWSEC2/latest/UserGuide/ec2-instance-connect-tutorial.md index 83ae0055d..3fc143bc7 100644 --- a//AWSEC2/latest/UserGuide/ec2-instance-connect-tutorial.md +++ b//AWSEC2/latest/UserGuide/ec2-instance-connect-tutorial.md @@ -73 +73 @@ JSON -The IAM policy created in this tutorial is a highly permissive policy; it allows you to connect to any instance using any AMI username. We're using this highly permissive policy to keep the tutorial simple and focused on the specific configurations that this tutorial is teaching. However, in a production environment, we recommend that your IAM policy is configured to provide [least-privilege permissions](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege). For example IAM policies, see [Grant IAM permissions for EC2 Instance Connect](./ec2-instance-connect-configure-IAM-role.html). +The IAM policy created in this tutorial is a highly permissive policy; it allows you to connect to any instance using any AMI username. This tutorial uses this highly permissive policy to keep the tutorial simple and focused on the specific configurations that this tutorial is teaching. However, in a production environment, we recommend that your IAM policy is configured to provide [least-privilege permissions](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege). For example IAM policies, see [Grant IAM permissions for EC2 Instance Connect](./ec2-instance-connect-configure-IAM-role.html). @@ -178 +178 @@ For example, if your instance is located in the US East (N. Virginia) (`us-east- -When you launch an instance, you must specify an AMI that contains the information required to launch the instance. You can choose to launch an instance with or without EC2 Instance Connect pre-installed. In this task, we specify an AMI that comes pre-installed with EC2 Instance Connect. +When you launch an instance, you must specify an AMI that contains the information required to launch the instance. You can choose to launch an instance with or without EC2 Instance Connect pre-installed. In this task, you specify an AMI that comes pre-installed with EC2 Instance Connect.