AMI sharing targets need review

Review AMI launch permissions and limit image use to approved accounts.

Description

An AMI's launch_permissions determine who can use the image to launch instances. Distributing an AMI to several approved accounts is a legitimate operating model, but including unnecessary accounts or a public group broadens its use beyond the intended audience. group_names: ['all'] configures public sharing.

Images intended for sharing must not contain passwords, keys, or internal data. Permission to launch an AMI is separate from permission to log in to a running instance.

Potential impact

  • Configuration details or sensitive data left in the image may reach unauthorized users.
  • Use in unintended accounts can make image versions and distribution harder to manage.

Remediation

  • Remove the public group unless public distribution is intended, and allow only approved accounts. Necessary sharing does not need to be removed merely because it involves multiple accounts.
  • When changing launch_permissions, specify every target that should retain access. Supplying only some targets can remove other existing launch permissions.
  • Remove secrets and internal data before sharing, and periodically review sharing targets and image versions.

Examples

These excerpts require an actual AMI and approved account IDs.

Before

yaml
- name: Update AMI Launch Permissions, making it public
  amazon.aws.ec2_ami:
    image_id: "{{ instance.image_id }}"
    state: present
    launch_permissions:
      group_names: ['all']

The public group receives permission to launch the AMI. This is unsuitable for an internal image.

After

yaml
- name: Allow AMI to be launched by another account
  amazon.aws.ec2_ami:
    image_id: "{{ instance.image_id }}"
    state: present
    launch_permissions:
      user_ids: ['123456789012']

Sharing is restricted to the specified account. If distribution requires multiple accounts, include all approved accounts in the list.

References