Description
An AMI's launch_permissions determine who can use the image to launch instances. Distributing an AMI to several approved accounts is a legitimate operating model, but including unnecessary accounts or a public group broadens its use beyond the intended audience. group_names: ['all'] configures public sharing.
Images intended for sharing must not contain passwords, keys, or internal data. Permission to launch an AMI is separate from permission to log in to a running instance.
Potential impact
- Configuration details or sensitive data left in the image may reach unauthorized users.
- Use in unintended accounts can make image versions and distribution harder to manage.
Remediation
- Remove the public group unless public distribution is intended, and allow only approved accounts. Necessary sharing does not need to be removed merely because it involves multiple accounts.
- When changing
launch_permissions, specify every target that should retain access. Supplying only some targets can remove other existing launch permissions. - Remove secrets and internal data before sharing, and periodically review sharing targets and image versions.
Examples
These excerpts require an actual AMI and approved account IDs.
Before
- name: Update AMI Launch Permissions, making it public
amazon.aws.ec2_ami:
image_id: "{{ instance.image_id }}"
state: present
launch_permissions:
group_names: ['all']
The public group receives permission to launch the AMI. This is unsuitable for an internal image.
After
- name: Allow AMI to be launched by another account
amazon.aws.ec2_ami:
image_id: "{{ instance.image_id }}"
state: present
launch_permissions:
user_ids: ['123456789012']
Sharing is restricted to the specified account. If distribution requires multiple accounts, include all approved accounts in the list.