Credentials are embedded in a CloudFormation template

Remove template secrets and use role-based access or a supported secret-management method.

Description

Embedding secret access keys or passwords in a CloudFormation template exposes them to readers of the template and its repository history. Leaked credentials may be used for the AWS or external-service operations they permit.

For cfn-init retrieval from S3, roleName can select the role in the attached instance profile. A NoEcho input does not protect a value subsequently exposed in Metadata or Outputs.

Potential impact

  • Leaked credentials may allow unauthorized operations on permitted resources.
  • Reusing the same values across environments can complicate replacement and impact assessment.

Remediation

For S3 access, use a least-privilege instance role with roleName. Pass other secrets through references supported by the property or retrieve them at runtime, and prevent exposure in logs or metadata. Revoke and replace confirmed leaked credentials and investigate their use.

Examples

These authentication excerpts omit instance properties such as the AMI and the cfn-init execution and file settings. WebServerRole must be the actual role in WebServerInstanceProfile and have the necessary S3 permissions.

Before

yaml
Resources:
  WebServer:
    Type: AWS::EC2::Instance
    Metadata:
      AWS::CloudFormation::Authentication:
        S3AccessCreds:
          type: S3
          accessKeyId: AKIAIOSFODNN7EXAMPLE
          secretKey: very-secret-value

The example access key and secret key are embedded in metadata. Do not store operational credentials this way.

After

yaml
Resources:
  WebServer:
    Type: AWS::EC2::Instance
    Metadata:
      AWS::CloudFormation::Authentication:
        S3AccessCreds:
          type: S3
          roleName: !Ref WebServerRole
    Properties:
      IamInstanceProfile: !Ref WebServerInstanceProfile

S3 authentication uses the instance-profile role. Associate this authentication configuration with the cfn-init file or source settings and verify access without static keys.

References