How to Access Amazon S3 from an EC2 Instance Using an IAM Role and IMDSv2 Credentials
CS Browser
Free Windows client for Amazon S3 and Amazon S3 compatible storage services
 
Follow

Access Amazon S3 from EC2 with an IAM Role

An IAM role lets CS Browser access Amazon S3 from an EC2 instance without storing or distributing long-term AWS access keys on the instance. Attach the role through an instance profile when launching the instance, or attach it to an existing instance.

Grant the role only the Amazon S3 permissions that CS Browser needs. For configuration instructions, see IAM roles for Amazon EC2 in the AWS documentation.

CS Browser retrieves temporary security credentials from the EC2 Instance Metadata Service using IMDSv2. The credentials include an access key ID, secret access key, and session token. AWS rotates them automatically and makes replacement credentials available before the current credentials expire.

To access Amazon S3 from EC2 using an IAM role:

  1. Start CS Browser and choose Accounts > Add new account.

    Accounts menu with Add new account selected
    Choose Accounts > Add new account, or press Ctrl+Alt+N.

    The Add New Account dialog will open:

    Add New Account dialog for an EC2 IAM role
    Add New Account dialog with Amazon S3 via EC2 IAM Role selected
  2. Enter any name that helps you identify the account in Display name.

  3. Choose Amazon S3 via EC2 IAM Role as the account type.

  4. Click Add new account.

    You can now choose the newly added account from the Accounts menu:

    Accounts menu with the selected account highlighted
    Select the newly added account from the Accounts menu, or use the shortcut shown next to it.

Advanced Account Settings

You may also configure additional settings when adding a new account or editing an existing account.

To open advanced account settings, click the advanced settings link located at the bottom-left corner of the dialog.

The Advanced Account Settings dialog will open:

Advanced storage settings dialog
Advanced account settings

You can configure the following settings:

Use dual-stack endpoints (IPv4/IPv6) - When selected, CS Browser uses dual-stack endpoints to access Amazon S3 over IPv4 or IPv6.

List all my buckets when account assigned - CS Browser calls the Amazon S3 ListBuckets operation when the account is assigned. This requires the s3:ListAllMyBuckets permission. If the role does not have this permission, clear the option to avoid failed tasks and warnings in the log.

Check CloudFront distributions when account assigned - CS Browser calls the CloudFront ListDistributions operation when the account is assigned. This requires the cloudfront:ListDistributions permission and lets CS Browser mark buckets used as CloudFront origins. If the role does not have this permission, clear the option.

Use Amazon S3 Transfer Acceleration - Uses a Transfer Acceleration endpoint for file transfers. Enable this option only for buckets where Transfer Acceleration is configured.

External Buckets - Enter one bucket or bucket/path value per line. Use / to separate a bucket name from an optional path, for example my-bucket/optional/path.

CS Browser 13.5.5 Freeware
Powered by Amazon Web Services and Rated by CNET Editors!
Social Connection
 
People like CS Browser!
People like us
Our customers say

"CS Browser is an invaluable tool to me as a web developer to easily manage my automated site backups" -Bob Kraft, Web Developer

"Just want to show my appreciation for a wonderful product. I use CS Browser a lot, it is a great tool." -Gideon Kuijten, Pro User

"Thank You Thank You Thank You for this tool. A must have for anyone using Amazon S3!" -Brian Cummiskey, USA

Related Products
RdpGuard
protects your Windows Server from RDP Brute-force Attacks.
CS Browser is developed by Netsdk Software FZE and is not affiliated with, endorsed by, or sponsored by Amazon or AWS. Amazon S3 and Amazon S3 Glacier are trademarks of Amazon.com, Inc. or its affiliates.
Copyright © 2008-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.  Mount Amazon S3 Bucket.  RDP brute-force protection.