Description
A private key stored in UserData as Base64 can be decoded easily. Encoding is not encryption, and anyone who can read the template or instance user data may obtain the secret.
Potential impact
If the exposed key is used for authentication, its access privileges could be misused.
Remediation
Remove private keys from UserData and revoke and replace exposed keys. If a secret is necessary, retrieve it at runtime from a dedicated store using an instance role with only the required permissions. Keep it out of logs and deployment artifacts.
Examples
These examples use a supported launch template. Supply ImageId and a compatible InstanceType. The original Base64 value imitates a private-key header and is not a real key. The revised example uses Fn::Base64 to encode a startup script containing no secrets.
Before
{
"Parameters": {
"ImageId": {
"Type": "AWS::EC2::Image::Id"
},
"InstanceType": {
"Type": "String"
}
},
"Resources": {
"myLaunchConfig3": {
"Type": "AWS::EC2::LaunchTemplate",
"Properties": {
"LaunchTemplateData": {
"ImageId": {
"Ref": "ImageId"
},
"InstanceType": {
"Ref": "InstanceType"
},
"UserData": "LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpzb21lS2V5"
}
}
}
}
}
After
{
"Parameters": {
"ImageId": {
"Type": "AWS::EC2::Image::Id"
},
"InstanceType": {
"Type": "String"
}
},
"Resources": {
"myLaunchConfig3": {
"Type": "AWS::EC2::LaunchTemplate",
"Properties": {
"LaunchTemplateData": {
"ImageId": {
"Ref": "ImageId"
},
"InstanceType": {
"Ref": "InstanceType"
},
"UserData": {
"Fn::Base64": "#!/bin/sh\necho bootstrap only\n"
}
}
}
}
}
}