Configuring service access for a Beanstalk Standard environment
A Beanstalk Standard environment uses a service role that Elastic Beanstalk assumes on your behalf and an Amazon EC2 instance profile that its instances assume. For details about these roles and how to create them, see Elastic Beanstalk Service roles, instance profiles, and user policies.
Environment security configuration namespaces
Elastic Beanstalk provides configuration options in the following namespaces to enable you to customize the security of your environment:
-
aws:elasticbeanstalk:environment – Configure the environment's service role using the
ServiceRoleoption. -
aws:autoscaling:launchconfiguration – Configure permissions for the environment's Amazon EC2 instances using the
EC2KeyName,IamInstanceProfile,DisableDefaultEC2SecurityGroup, andSecurityGroupsoptions.
The EB CLI and Elastic Beanstalk console apply recommended values for the preceding options. You must remove these settings if you want to use configuration files to configure the same. See Recommended values for details.