Review encryption of AMI EBS snapshots

Apply the required encryption at rest to the snapshots behind EBS-backed AMIs.

Description

An EBS-backed AMI stores its data in associated snapshots. Unencrypted snapshots may fail the required encryption-at-rest policy. Check the actual snapshot encryption state as well as the AMI creation settings.

Potential impact

Application data and configuration retained in the image lack encryption-at-rest protection. AMI and snapshot sharing permissions still control access independently of encryption.

Remediation

Create an encrypted copy of an unencrypted AMI and use the new image for subsequent deployments. Creating an AMI from an existing instance cannot change the encryption state of its volumes.

Examples

The first task creates an AMI from an instance. The revised task makes an encrypted copy of a separately prepared source AMI. Supply the actual instance ID, source image, and region values.

Before

yaml
- name: Basic AMI Creation
  amazon.aws.ec2_ami:
    instance_id: i-xxxxxx
    wait: yes
    name: newtest

After

yaml
- name: Copy AMI with encryption
  community.aws.ec2_ami_copy:
    source_image_id: "{{ source_ami_id }}"
    source_region: "{{ source_region }}"
    region: "{{ target_region }}"
    encrypted: true
    wait: true
    name: newtest

References