EBS encryption in EC2 launch settings needs review

Verify EBS encryption in EC2 launch settings and plan both launch-template updates and the transition of existing instances.

Description

Reusing EC2 launch settings without the required EBS encryption can create unencrypted volumes across multiple instances. Review the AMI's mappings, source snapshots and regional EBS encryption defaults together. Encrypted snapshots or regional defaults can encrypt new volumes even without an explicit encryption request.

Legacy Auto Scaling launch configurations cannot be modified after creation. Use launch templates for new configurations and plan a supported migration for groups that still use launch configurations.

Potential impact

  • Repeatedly creating actually unencrypted volumes can increase the number of resources that fail organizational data-protection requirements.
  • Changing launch settings leaves the existing volumes of running instances unchanged.

Remediation

  • Configure encryption and KMS permissions for the actual EBS mappings. Check both the AMI's root volume and additional data volumes, and distinguish instance store from EBS.
  • Prepare the required launch-template version and configure the Auto Scaling group to use it. Verify new instances' volume encryption and operation before replacing instances with service availability in mind.
  • Plan existing unencrypted data migration, connection changes and downtime separately. Updating a template does not encrypt existing volumes.

Examples

These launch-template examples add a new blank data volume. Supply the actual ami_id and security group ID list, and ensure /dev/sdf does not conflict with the AMI's existing mappings. Configure root-volume encryption and the Auto Scaling group association separately.

No explicit encryption request

yaml
- name: EBS encryption for new instances
  amazon.aws.ec2_launch_template:
    name: special
    image_id: "{{ ami_id }}"
    security_group_ids: "{{ security_group_ids }}"
    instance_type: t3.micro
    block_device_mappings:
      - device_name: /dev/sdf
        ebs:
          volume_size: 100
          volume_type: gp3
          delete_on_termination: true
          encrypted: false

The additional data volume does not explicitly request encryption. Regional encryption defaults can still encrypt the actual new volume.

Request encryption for the new data volume

yaml
- name: EBS encryption for new instances
  amazon.aws.ec2_launch_template:
    name: special
    image_id: "{{ ami_id }}"
    security_group_ids: "{{ security_group_ids }}"
    instance_type: t3.micro
    block_device_mappings:
      - device_name: /dev/sdf
        ebs:
          volume_size: 100
          volume_type: gp3
          delete_on_termination: true
          encrypted: true

This requests encryption for the new data volume. Verify the actual volume and KMS access on instances launched with this template version. It does not change volumes on already running instances.

References