Restrict commands via SSH like curl http://169.254.169.254/latest/meta-data/iam/security-credentials/role_name
.
$ sudo adduser -m vuls
$ sudo su vuls
$ mkdir -m 700 /home/vuls/.ssh
$ curl https://raw.githubusercontent.com/asannou/vuls-ssh-command/0.9.1/vuls-ssh-command.sh > /home/vuls/.ssh/vuls-ssh-command.sh
$ chmod +x /home/vuls/.ssh/vuls-ssh-command.sh
$ echo 'command="/home/vuls/.ssh/vuls-ssh-command.sh" ssh-rsa ...' > /home/vuls/.ssh/authorized_keys