Description
A private key embedded in EC2 user data can be read by users or software with access to that data. Base64 is an encoding format, not encryption. First distinguish private keys from public keys and certificates in PEM content.
Potential impact
An exposed private key that is actually in use may be misused for authentication or signing, depending on its purpose and protection. Public certificates and illustrative strings should not be treated as leaked private keys.
Remediation
Remove secrets from user data and retrieve them from a dedicated store such as AWS Secrets Manager through an instance role with only the necessary permissions. Revoke or replace exposed keys and update their consumers. Check for copies in old launch configurations, template versions and instances.
Examples
Use an EC2 launch template for new configurations. Set ami_id and security_group_ids to actual resources and ensure the default key pair exists. This module accepts Base64-encoded user_data.
Before
- name: launch template with illustrative encoded key material
amazon.aws.ec2_launch_template:
name: special
image_id: "{{ ami_id }}"
key_name: default
security_group_ids: "{{ security_group_ids }}"
instance_type: t3.micro
user_data: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpzb21lS2V5
The example encodes -----BEGIN RSA PRIVATE KEY----- followed by someKey, not a complete private key. Do not embed a real key this way.
After
- name: launch template without embedded private key
amazon.aws.ec2_launch_template:
name: special
image_id: "{{ ami_id }}"
key_name: default
security_group_ids: "{{ security_group_ids }}"
instance_type: t3.micro
user_data: IyEvYmluL3NoCmV4aXQgMAo=
The replacement encodes a no-op initialization script: #!/bin/sh followed by exit 0. It contains no secret; configure the application's secret retrieval separately.
References
- CWE-326
- Ansible community.aws.ec2_lc documentation
- community.aws 1.5.0 ec2_lc implementation
- botocore 1.20.106 user-data encoding
- CreateLaunchConfiguration API
- Current autoscaling_launch_config module
- EC2 metadata and user-data access
- Launch configuration limits and migration to launch templates
- Secrets Manager best practices
- RFC 7468: Textual encodings of certificates and keys
- Ansible EC2 launch template module