Description
Snapshots backing an EBS-based AMI store operating-system and application data. An unencrypted snapshot lacks protection at rest, and reusing the image can spread configurations that fail encryption requirements.
For an AMI that references a snapshot, check the snapshot's actual encryption state. Omission of encrypted does not establish that it is unencrypted. EBS encryption by default at instance launch does not retroactively encrypt existing AMI snapshots either.
Potential impact
Unauthorized access to snapshots or disk data can increase the risk of disclosure. Encryption at rest does not replace AMI sharing controls or access restrictions within an instance.
Remediation
- Verify encryption and required KMS permissions for every EBS snapshot associated with the AMI.
- Copy an existing AMI with encryption enabled, or register a new AMI using encrypted snapshots. The
aws_amiresource cannot combinesnapshot_idwithencrypted. - Test booting and application operation with the new image before updating deployment references. Existing instances and snapshots are not automatically encrypted; plan their migration and retention separately.
Examples
These excerpts show AMI registration. Replace snap-xxxxxxxx with an actual snapshot ID. The snapshot must support booting from the specified root device and be no larger than the example's 8 GiB volume.
Snapshot reference
resource "aws_ami" "example" {
name = "terraform-example"
virtualization_type = "hvm"
root_device_name = "/dev/xvda"
ebs_block_device {
device_name = "/dev/xvda"
snapshot_id = "snap-xxxxxxxx"
volume_size = 8
}
}
If the referenced snapshot is unencrypted, the AMI retains that backing snapshot. Omitting an encryption attribute does not reveal the source snapshot's state.
Encrypted snapshot reference
resource "aws_ami" "example" {
name = "terraform-example"
virtualization_type = "hvm"
root_device_name = "/dev/xvda"
ebs_block_device {
device_name = "/dev/xvda"
snapshot_id = var.encrypted_snapshot_id
volume_size = 8
}
}
Supply the actual ID of an already encrypted snapshot through var.encrypted_snapshot_id. Adding encrypted = true during AMI registration is not a supported way to convert an existing snapshot.