Is it possible to provide Vault token to EC2 instances initiated by EMR cluster?

The flow: Each time EMR create a new EC2 instance - we need automatically setup Vault Agent on it… So, what will be the best way to provide RoleID and SecretID for agent configuration?