Use IAM Tags to Restrict EC2 Instances or EBS Volumes

    "Version": "2012-10-17",
    "Statement": [
            "Sid": "AllowToDescribeAll",
            "Effect": "Allow",
            "Action": [
            "Resource": "*"
            "Sid": "AllowRunInstances",
            "Effect": "Allow",
            "Action": "ec2:RunInstances",
            "Resource": [
            "Sid": "AllowRunInstancesWithRestrictions",
            "Effect": "Allow",
            "Action": [
            "Resource": [
            "Condition": {
                "StringEquals": {
                    "aws:RequestTag/key1": "value1",
                    "aws:RequestTag/key2": "value2"
                "ForAllValues:StringEquals": {
                    "aws:TagKeys": [
            "Sid": "AllowCreateTagsOnlyLaunching",
            "Effect": "Allow",
            "Action": [
            "Resource": [
            "Condition": {
                "StringEquals": {
                    "ec2:CreateAction": "RunInstances"


