Compute

Compute in AWS is where IAM meets code execution. Almost every compute service runs with an attached role, so taking over a workload, or launching one you control, yields that role's credentials and whatever it can reach. The same services also hold secrets at rest: user-data scripts, snapshots, images, and environment configuration. The pages here work both angles, stealing the role and reading the data.

Surfaces#

  • EC2: user-data secrets and code, the instance profile role, and data recovery from EBS snapshots and shared AMIs.
  • SSM: Systems Manager run command and Session Manager shells on managed instances, under the instance role.
  • Containers: ECS and EKS task-role theft, task-definition abuse, and the container runtime.
  • ECR: pulling from exposed repositories and poisoning images that downstream compute will run.
  • Elastic Beanstalk: environments, their instance-profile role, and secrets in configuration.
  • Image Builder: pipelines and components that bake code into golden AMIs.
  • App Runner: services and their instance role, and source or image deployment.
  • Batch: job definitions and compute environments running containers under a job role.
  • Lightsail: instances, keys, and snapshots that sit outside the main VPC and IAM visibility.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more