Description
Share an AMI only with AWS accounts that need it. Sharing with several approved accounts can be a legitimate operating model, and sharing with specific accounts does not make an image public. However, a growing list of recipients makes image use harder to control.
An AMI can contain application code, agents, and operational settings. Unnecessary launch permissions can spread these assets into environments that do not follow internal standards.
Potential impact
- Wider image distribution: accounts without a business need can launch instances from the AMI.
- Weaker operational control: it becomes harder to track which accounts use each image.
- Possible disclosure of sensitive settings: image configuration and agent settings can reach more environments.
Remediation
- Share each AMI with only the accounts that need it.
- Manage reusable shared images separately from images intended for individual accounts.
- Review
aws_ami_launch_permissionregularly and remove launch permissions for accounts that no longer need them.
Examples
The AMI and account IDs are illustrative. Use an AMI you own in the relevant Region and approved 12-digit account IDs.
Before
resource "aws_ami_launch_permission" "example_a" {
image_id = "ami-0abcdef1234567890"
account_id = "123456789012"
}
resource "aws_ami_launch_permission" "example_b" {
image_id = "ami-0abcdef1234567890"
account_id = "111122223333"
}
After
resource "aws_ami_launch_permission" "example_a" {
image_id = "ami-0abcdef1234567890"
account_id = "123456789012"
}
Before the change, two accounts can launch the same AMI. Afterward, only the approved first account retains that permission. Keep both permissions if both accounts need them, and separately review images that have already been deployed or copied.