Create an IAM Role called 'paas-ec2' with the managed policies AmazonEC2RoleforSSM and AmazonS3ReadOnlyAccess. The template refers specifically to the name 'paas-ec2'.