Review encoded key material in user data

Check whether user data contains an actual private key. Base64 encoding does not protect secrets.

Description

A private key embedded in EC2 user data can be read by users or software with access to that data. Base64 is an encoding format, not encryption. First distinguish private keys from public keys and certificates in PEM content.

Potential impact

An exposed private key that is actually in use may be misused for authentication or signing, depending on its purpose and protection. Public certificates and illustrative strings should not be treated as leaked private keys.

Remediation

Remove secrets from user data and retrieve them from a dedicated store such as AWS Secrets Manager through an instance role with only the necessary permissions. Revoke or replace exposed keys and update their consumers. Check for copies in old launch configurations, template versions and instances.

Examples

Use an EC2 launch template for new configurations. Set ami_id and security_group_ids to actual resources and ensure the default key pair exists. This module accepts Base64-encoded user_data.

Before

yaml
- name: launch template with illustrative encoded key material
  amazon.aws.ec2_launch_template:
    name: special
    image_id: "{{ ami_id }}"
    key_name: default
    security_group_ids: "{{ security_group_ids }}"
    instance_type: t3.micro
    user_data: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpzb21lS2V5

The example encodes -----BEGIN RSA PRIVATE KEY----- followed by someKey, not a complete private key. Do not embed a real key this way.

After

yaml
- name: launch template without embedded private key
  amazon.aws.ec2_launch_template:
    name: special
    image_id: "{{ ami_id }}"
    key_name: default
    security_group_ids: "{{ security_group_ids }}"
    instance_type: t3.micro
    user_data: IyEvYmluL3NoCmV4aXQgMAo=

The replacement encodes a no-op initialization script: #!/bin/sh followed by exit 0. It contains no secret; configure the application's secret retrieval separately.

References