For my own AWS accounts, I use a read-only account in the profile and, on the very rare occasion I want to get clicky rather than use awscli to frob something, I'll log out and log back in as my writable-to-IAM user. I have a third user that only has IAM read/write privileges if I have to deal with that service. (I haven't sold my clients on this approach, though.)
Ha, I do the same thing. I learned about this from a previous job I had where prod/test webapps were functionally similar but had obnoxious coloring in the header. Very effective.
echo '\033]11;#440000\007'
On the local machine add this to reset the terminal color: ssh () {/usr/bin/ssh "$@"; echo '\033]11;#000000\007'} <body style="foo bar baz env-#{Rails.environment}">
Then use CSS like you would normally on body.env-production, body.env-development, etc. <body class="foo bar baz env-#{Rails.environment}">Could make a nice Chrome extension...
Let's say you have a bug or SQL injection in a web app (or choose any server): the user running the web app and/or database now has access to your AWS account.
Instance profiles are available to every user and process on the server for the life of the server.
Layering multiple least-privilege roles is impossible: you can't assign multiple IAM roles to an instance.
You can't separate what process receives access to those credentials.
The old-school way of embedding credentials in a config file and make it readable only by root and/or a specific user account on the system is currently the best solution. Better, but more challenging at scale, are SE-Linux, AppArmor, etc.
You can assign multiple IAM roles to an instance profile, which is what is associated with an instance.
See e.g. [0]; you can add IAM roles to instance profiles without destroying the instance.
[0] https://docs.aws.amazon.com/cli/latest/reference/iam/add-rol...
Perhaps there is some contradiction in the IAM docs, but I couldn't find that reference. This seems to indicate that only one role can be assigned to an instance profile:
"Note that only one role can be assigned to an Amazon EC2 at a time, and all applications on the instance share the same role and permissions." (first paragraph, last sentence)
http://docs.aws.amazon.com/IAM/latest/UserGuide/roles-usingr...
The main takeaway here is to always use IAM accounts when doing stuff with AWS, and make sure each IAM account is only permitted to do the things you want it to do. It might be a pain in the ass to learn how the IAM policy syntax works, but believe me it works out for you in the long run!
(And, of course, use multi-factor auth. But you should be doing that anyway...)