Description
Ansible's aws_access_key field takes the access key ID used to authenticate AWS requests, not the secret access key. Putting a real secret key there can cause authentication failures while leaving the secret in playbooks or deployment records. Check whether a suspicious value is a public example or an actual secret.
Ansible deployment authentication and the Lambda execution role have different purposes. The task's role supplies the role used by the running function to access AWS resources; it does not authenticate Ansible's deployment requests.
Potential impact
- If a real secret key and the other required authentication details are exposed, they can be used for unwanted AWS requests within their permission scope.
- Incorrect authentication fields can break deployments. An exposed shared key also requires investigation and updates to other workloads using it.
Remediation
- Do not embed real credentials in the playbook. Use temporary credentials or external authentication settings supported by the module's execution environment.
- Assign the function an execution role with the permissions it needs. Apply least privilege separately to the deployment identity and function execution role.
- Promptly deactivate or revoke and replace a valid exposed key. Investigate repository history, deployment records and access logs, update dependent workloads, then verify deployment and function behavior.
Examples
The key string is a public AWS documentation example, not a real credential. Supply lambda_functions as a list of items with name and zip_file, and set lambda_runtime to a supported runtime compatible with the code. Prepare the execution role ARN and deployment files separately.
Before
- name: looped creation
amazon.aws.lambda:
aws_access_key: "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
name: "{{ item.name }}"
state: present
zip_file: "{{ item.zip_file }}"
runtime: "{{ lambda_runtime }}"
role: "{{ lambda_execution_role_arn }}"
handler: "hello_python.my_handler"
loop: "{{ lambda_functions }}"
An example secret access key is incorrectly placed in the ID field. Do not supply real keys this way.
After
- name: looped creation
amazon.aws.lambda:
name: "{{ item.name }}"
state: present
zip_file: "{{ item.zip_file }}"
runtime: "{{ lambda_runtime }}"
role: "{{ lambda_execution_role_arn }}"
handler: hello_python.my_handler
loop: "{{ lambda_functions }}"
Credentials are supplied by the module's execution environment instead of being embedded. Because role controls the function's execution permissions, separate deployment authentication is still required. Removing the field does not revoke a previously exposed key.