Review AWS AMI account sharing

Verify that AMI sharing is limited to approved accounts and remove unnecessary launch permissions.

Description

Share an AMI only with AWS accounts that need it. Sharing with several approved accounts can be a legitimate operating model, and sharing with specific accounts does not make an image public. However, a growing list of recipients makes image use harder to control.

An AMI can contain application code, agents, and operational settings. Unnecessary launch permissions can spread these assets into environments that do not follow internal standards.

Potential impact

  • Wider image distribution: accounts without a business need can launch instances from the AMI.
  • Weaker operational control: it becomes harder to track which accounts use each image.
  • Possible disclosure of sensitive settings: image configuration and agent settings can reach more environments.

Remediation

  • Share each AMI with only the accounts that need it.
  • Manage reusable shared images separately from images intended for individual accounts.
  • Review aws_ami_launch_permission regularly and remove launch permissions for accounts that no longer need them.

Examples

The AMI and account IDs are illustrative. Use an AMI you own in the relevant Region and approved 12-digit account IDs.

Before

hcl
resource "aws_ami_launch_permission" "example_a" {
  image_id   = "ami-0abcdef1234567890"
  account_id = "123456789012"
}

resource "aws_ami_launch_permission" "example_b" {
  image_id   = "ami-0abcdef1234567890"
  account_id = "111122223333"
}

After

hcl
resource "aws_ami_launch_permission" "example_a" {
  image_id   = "ami-0abcdef1234567890"
  account_id = "123456789012"
}

Before the change, two accounts can launch the same AMI. Afterward, only the approved first account retains that permission. Keep both permissions if both accounts need them, and separately review images that have already been deployed or copied.

References