Description
Embedding secret access keys or passwords in a CloudFormation template exposes them to readers of the template and its repository history. Leaked credentials may be used for the AWS or external-service operations they permit.
For cfn-init retrieval from S3, roleName can select the role in the attached instance profile. A NoEcho input does not protect a value subsequently exposed in Metadata or Outputs.
Potential impact
- Leaked credentials may allow unauthorized operations on permitted resources.
- Reusing the same values across environments can complicate replacement and impact assessment.
Remediation
For S3 access, use a least-privilege instance role with roleName. Pass other secrets through references supported by the property or retrieve them at runtime, and prevent exposure in logs or metadata. Revoke and replace confirmed leaked credentials and investigate their use.
Examples
These authentication excerpts omit instance properties such as the AMI and the cfn-init execution and file settings. WebServerRole must be the actual role in WebServerInstanceProfile and have the necessary S3 permissions.
Before
Resources:
WebServer:
Type: AWS::EC2::Instance
Metadata:
AWS::CloudFormation::Authentication:
S3AccessCreds:
type: S3
accessKeyId: AKIAIOSFODNN7EXAMPLE
secretKey: very-secret-value
The example access key and secret key are embedded in metadata. Do not store operational credentials this way.
After
Resources:
WebServer:
Type: AWS::EC2::Instance
Metadata:
AWS::CloudFormation::Authentication:
S3AccessCreds:
type: S3
roleName: !Ref WebServerRole
Properties:
IamInstanceProfile: !Ref WebServerInstanceProfile
S3 authentication uses the instance-profile role. Associate this authentication configuration with the cfn-init file or source settings and verify access without static keys.