To ensure there was no way for one user’s data to mingle with another, each cloud instance had its own dedicated VM, databaseNo this will not protect you. Understanding the proper way to configure IAM roles with principle of least privilege will.
The author mentions that The issue here is Octopus is like a CI server - customers can run arbitrary code in the instance (not a problem most SaaS apps have). So a VM per customer was almost the bare minimum.
If you're using the same IAM role for your EC2 instances, and you're allowing your customers to run arbitrary code, well now at the very least they have access to everyone's databases.