Compute in AWS is where IAM meets code execution. Almost every compute service runs with an attached role, so taking over a workload, or launching one you control, yields that role's credentials and whatever it can reach. The same services also hold secrets at rest: user-data scripts, snapshots, images, and environment configuration. The pages here work both angles, stealing the role and reading the data.
Surfaces#
- EC2: user-data secrets and code, the instance profile role, and data recovery from EBS snapshots and shared AMIs.
- SSM: Systems Manager run command and Session Manager shells on managed instances, under the instance role.
- Containers: ECS and EKS task-role theft, task-definition abuse, and the container runtime.
- ECR: pulling from exposed repositories and poisoning images that downstream compute will run.
- Elastic Beanstalk: environments, their instance-profile role, and secrets in configuration.
- Image Builder: pipelines and components that bake code into golden AMIs.
- App Runner: services and their instance role, and source or image deployment.
- Batch: job definitions and compute environments running containers under a job role.
- Lightsail: instances, keys, and snapshots that sit outside the main VPC and IAM visibility.