AWS AWSEC2: Added launch template permission checks for EC2 Fast Launch
Summary
Documented IAM permission risks when using $Latest/$Default launch template versions with EC2 Fast Launch.
Security assessment
Explicitly describes privilege escalation risk where unauthorized users could bypass iam:PassRole via template updates.
Evidence
+As a result, someone who can update the launch template could pass an IAM role or instance profile to an instance. This can happen even if they don't have the `iam:PassRole` permission for that role.
Diff
diff --git a/AWSEC2/latest/UserGuide/win-fast-launch-configure.md b/AWSEC2/latest/UserGuide/win-fast-launch-configure.md index 5d34ac147..3bdd5dd71 100644 --- a//AWSEC2/latest/UserGuide/win-fast-launch-configure.md +++ b//AWSEC2/latest/UserGuide/win-fast-launch-configure.md @@ -7 +7 @@ -Enable EC2 Fast LaunchDisable EC2 Fast LaunchUse a launch template +Enable EC2 Fast LaunchDisable EC2 Fast LaunchUse a launch templatePermissions checks @@ -199 +199 @@ Use the launch template that includes your metadata configuration from the EC2 c -Amazon EC2 EC2 Fast Launch doesn't support the following configuration when you use a launch template. If you use a launch template for EC2 Fast Launch, you must not specify any of the following: +EC2 Fast Launch doesn't support the following configuration when you use a launch template. If you use a launch template for EC2 Fast Launch, you must not specify any of the following: @@ -278,0 +279,12 @@ For more information about EC2 launch templates, see [Store instance launch para +## Permissions checks for EC2 Fast Launch + +When you enable EC2 Fast Launch with a launch template, you can specify a numbered version of the template. You can also use the `$Latest` or `$Default` version. If you use one of the aliases, the alias can override the `ec2:RunInstances` and `iam:PassRole` permissions that you intended to restrict. + +When you enable EC2 Fast Launch, Amazon EC2 checks your permissions against the current launch template version. `$Latest` and `$Default` each resolve to a specific version at that time. This check runs before Amazon EC2 enables the feature. It validates the permissions required to launch instances, such as the `ec2:RunInstances` and `iam:PassRole` permissions. To do this, EC2 Fast Launch issues a `RunInstances` dry run call that checks your permissions without launching an instance. If your permissions don't allow a required action, Amazon EC2 fails the request and returns an error that describes the missing permission. Amazon EC2 does not enable EC2 Fast Launch. + +After this initial check is complete, EC2 Fast Launch creates the pre-provisioned snapshots in the background. It then launches instances by using the permissions of its service-linked role. Each time it launches an instance, it uses the version that `$Latest` or `$Default` resolves to at that time. This is true even if the version has changed after the initial check. It does not recheck your permissions. As a result, someone who can update the launch template could pass an IAM role or instance profile to an instance. This can happen even if they don't have the `iam:PassRole` permission for that role. + +To make sure that Amazon EC2 always uses the version it validated when you enabled the feature, specify a numbered launch template version. Do not use `$Latest` or `$Default`. + +If you configure EC2 Fast Launch to use the `$Latest` or `$Default` launch template version, we recommend that you limit who can create and manage launch template versions. Use IAM policies to restrict access to actions such as `ec2:CreateLaunchTemplateVersion` and `ec2:ModifyLaunchTemplate`. +