Unencrypted AWS AMI

Check the backing snapshots of EBS-based AMIs and migrate to encrypted images.

Description

Snapshots backing an EBS-based AMI store operating-system and application data. An unencrypted snapshot lacks protection at rest, and reusing the image can spread configurations that fail encryption requirements.

For an AMI that references a snapshot, check the snapshot's actual encryption state. Omission of encrypted does not establish that it is unencrypted. EBS encryption by default at instance launch does not retroactively encrypt existing AMI snapshots either.

Potential impact

Unauthorized access to snapshots or disk data can increase the risk of disclosure. Encryption at rest does not replace AMI sharing controls or access restrictions within an instance.

Remediation

  • Verify encryption and required KMS permissions for every EBS snapshot associated with the AMI.
  • Copy an existing AMI with encryption enabled, or register a new AMI using encrypted snapshots. The aws_ami resource cannot combine snapshot_id with encrypted.
  • Test booting and application operation with the new image before updating deployment references. Existing instances and snapshots are not automatically encrypted; plan their migration and retention separately.

Examples

These excerpts show AMI registration. Replace snap-xxxxxxxx with an actual snapshot ID. The snapshot must support booting from the specified root device and be no larger than the example's 8 GiB volume.

Snapshot reference

hcl
resource "aws_ami" "example" {
  name                = "terraform-example"
  virtualization_type = "hvm"
  root_device_name    = "/dev/xvda"

  ebs_block_device {
    device_name = "/dev/xvda"
    snapshot_id = "snap-xxxxxxxx"
    volume_size = 8
  }
}

If the referenced snapshot is unencrypted, the AMI retains that backing snapshot. Omitting an encryption attribute does not reveal the source snapshot's state.

Encrypted snapshot reference

hcl
resource "aws_ami" "example" {
  name                = "terraform-example"
  virtualization_type = "hvm"
  root_device_name    = "/dev/xvda"

  ebs_block_device {
    device_name = "/dev/xvda"
    snapshot_id = var.encrypted_snapshot_id
    volume_size = 8
  }
}

Supply the actual ID of an already encrypted snapshot through var.encrypted_snapshot_id. Adding encrypted = true during AMI registration is not a supported way to convert an existing snapshot.

References