A cloud IAM (Identity and Access Management) construct that bundles permissions and can be temporarily 'assumed' by a user or service — eliminates the need to embed long-lived credentials in code or configuration.
IAM Roles are how cloud services securely access other cloud services without hardcoded keys. An EC2 instance attached to an IAM Role automatically gets temporary credentials to call AWS APIs scoped to the role's permissions. A Lambda function assumes its execution role. A user can assume a role for elevated access. Cross-account roles enable secure access across AWS accounts. Roles are short-lived (credentials rotate automatically) and auditable in CloudTrail, making them the right default for any service-to-service auth in AWS/GCP/Azure.
Granting a Lambda function read-only S3 access by attaching an IAM Role with `s3:GetObject` permissions on the relevant bucket — no embedded access keys.
IAM Roles are the right primitive for service-to-service cloud auth — embedded credentials in code are an audit-finding waiting to happen.
Need help implementing this in your business?
Get Started