AWS Security ChangesHomeSearch

AWS govcloud-us high security documentation change

Service: govcloud-us · 2026-06-10 · Security-related high

File: govcloud-us/latest/UserGuide/govcloud-ec2ib.md

Summary

Restructured documentation about EC2 Image Builder differences, added explicit guidance about export-controlled content restrictions

Security assessment

Added specific warnings about export-controlled data in metadata fields (names, descriptions, tags) which could lead to compliance violations if mishandled. Explicitly states that export-controlled data must not be entered in these fields.

Diff

diff --git a/govcloud-us/latest/UserGuide/govcloud-ec2ib.md b/govcloud-us/latest/UserGuide/govcloud-ec2ib.md
index c308402a6..24b7ee50d 100644
--- a//govcloud-us/latest/UserGuide/govcloud-ec2ib.md
+++ b//govcloud-us/latest/UserGuide/govcloud-ec2ib.md
@@ -7 +7 @@
-Service differencesDocumentation referencesExport-controlled content
+How Amazon EC2 Image Builder differsDocumentationExport-controlled content
@@ -9 +9 @@ Service differencesDocumentation referencesExport-controlled content
-# Amazon EC2 Image Builder in AWS GovCloud (US) Regions
+# Amazon EC2 Image Builder in AWS GovCloud (US)
@@ -11 +11 @@ Service differencesDocumentation referencesExport-controlled content
-Amazon EC2 Image Builder (Image Builder) is a fully managed AWS service that makes it easier to automate the creation, management, and deployment of customized, secure, and up-to-date server images that are pre-installed and pre-configured with software and settings to meet specific IT standards.
+Amazon Elastic Compute Cloud Image Builder is a fully managed AWS service that makes it easier to automate the creation, management and deployment of customized, secure and up-to-date “golden” server images that are pre-installed and pre-configured with software and settings to meet specific IT standards. You can use the AWS Management Console, AWS CLI or APIs to create “golden” images in your AWS account. The images you build are created in your account and you can configure them for operating system patches on an ongoing basis.
@@ -13 +13 @@ Amazon EC2 Image Builder (Image Builder) is a fully managed AWS service that mak
-## Service differences
+## How Amazon EC2 Image Builder differs
@@ -15 +15 @@ Amazon EC2 Image Builder (Image Builder) is a fully managed AWS service that mak
-The following Image Builder features are not available in AWS GovCloud (US) Regions:
+The following differences apply to Amazon EC2 Image Builder:
@@ -17,3 +17 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
-  * ISO disk file import
-
-  * macOS images
+  * Image Builder doesn’t support macOS images.
@@ -21 +19 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
-  * AWS Marketplace software components
+  * The following Image Builder features are not available:
@@ -22,0 +21 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
+    * Image lifecycle policies
@@ -23,0 +23 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
+    * AWS Marketplace Software components
@@ -24,0 +25 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
+    * ISO disk file import
@@ -26 +26,0 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
-## Documentation references
@@ -28 +27,0 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
-  * [EC2 Image Builder User Guide](https://docs.aws.amazon.com/imagebuilder/latest/userguide/)
@@ -30 +28,0 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
-  * [EC2 Image Builder AWS CLI Reference](https://docs.aws.amazon.com/cli/latest/reference/imagebuilder/index.html)
@@ -32 +30 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
-  * [EC2 Image Builder API Reference](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/)
+## Documentation
@@ -34 +32 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
-  * [AWS Developer Tools](./cli-and-api-access.html)
+For more information about Amazon EC2 Image Builder, see the [Amazon EC2 Image Builder documentation](https://docs.aws.amazon.com/imagebuilder/latest/userguide).
@@ -36 +34 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
-  * [Service endpoints](./using-govcloud-endpoints.html)
+## Export-controlled content
@@ -37,0 +36 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
+For AWS Services architected within the AWS GovCloud (US) Regions, the following list explains how certain components of data may leave the AWS GovCloud (US) Regions in the normal course of the service offerings. The list can be used as a guide to help meet applicable customer compliance obligations. Data not included in the following list remains within the AWS GovCloud (US) Regions.
@@ -38,0 +38 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
+  * EC2 Image Builder metadata is not permitted to contain export-controlled data. This metadata includes all configuration data that you enter when creating and maintaining your images, components, image recipes, distribution configurations and infrastructure configurations.
@@ -39,0 +40 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
+Do not enter export-controlled data in the following console fields:
@@ -41 +42 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
-## Export-controlled content
+    * Names
@@ -43 +44 @@ The following Image Builder features are not available in AWS GovCloud (US) Regi
-For AWS services architected within the AWS GovCloud (US) Region, the following list explains how certain components of data may leave the AWS GovCloud (US) Region in the normal course of the service offerings. The list can be used as a guide to help meet applicable customer compliance obligations. Data not included in the following list remains within the AWS GovCloud (US) Region.
+    * Description
@@ -45 +46 @@ For AWS services architected within the AWS GovCloud (US) Region, the following
-  * This service can generate metadata from customer-defined configurations. AWS suggests customers do not enter export-controlled information in console fields, descriptions, resource names, and tagging information.
+    * Resource tags