Description
An EBS-backed AMI stores its data in associated snapshots. Unencrypted snapshots may fail the required encryption-at-rest policy. Check the actual snapshot encryption state as well as the AMI creation settings.
Potential impact
Application data and configuration retained in the image lack encryption-at-rest protection. AMI and snapshot sharing permissions still control access independently of encryption.
Remediation
Create an encrypted copy of an unencrypted AMI and use the new image for subsequent deployments. Creating an AMI from an existing instance cannot change the encryption state of its volumes.
Examples
The first task creates an AMI from an instance. The revised task makes an encrypted copy of a separately prepared source AMI. Supply the actual instance ID, source image, and region values.
Before
- name: Basic AMI Creation
amazon.aws.ec2_ami:
instance_id: i-xxxxxx
wait: yes
name: newtest
After
- name: Copy AMI with encryption
community.aws.ec2_ami_copy:
source_image_id: "{{ source_ami_id }}"
source_region: "{{ source_region }}"
region: "{{ target_region }}"
encrypted: true
wait: true
name: newtest