AWS Security ChangesHomeSearch

AWS managedservices: Fix patch tag names and add IMDS whitespace warning

Service: managedservices · 2026-09-27 · Documentation low

File: managedservices/latest/accelerate-guide/acc-patching.md

Summary

Changed recommended patch tag names from 'Patch Group'/'Maintenance Window' to 'PatchGroup'/'MaintenanceWindow' and added a note that whitespace in a tag key fails validation when IMDS tags are enabled, causing the instance to drop the tag and miss patch events.

Security assessment

The change is operational guidance about patch tag naming and IMDS tag validation. It touches patch management (security-relevant) but does not address a specific vulnerability or incident; it prevents missed patch events due to tag validation failure.

Evidence

+Don't use spaces or other whitespace in a tag key. If you enable Instance Metadata Service (IMDS) tags on an instance, a tag key that contains whitespace fails validation. The instance then drops the tag and misses its scheduled patch events.

Diff

diff --git a/managedservices/latest/accelerate-guide/acc-patching.md b/managedservices/latest/accelerate-guide/acc-patching.md
index 204765ff1..0ebb4df92 100644
--- a//managedservices/latest/accelerate-guide/acc-patching.md
+++ b//managedservices/latest/accelerate-guide/acc-patching.md
@@ -71 +71,5 @@ The patching process for persistent instances should involve the following teams
-  * **The application (DevOps) teams** define the patch groups for their servers based on application environment, OS type, or other criteria. They also define the maintenance windows specific to each patch group. This information should be stored on tags attached to the instances. Recommended tag names are 'Patch Group' and 'Maintenance Window'. During each patch cycle, the application teams prepare for patching, test the application after patching, and troubleshoot any issues with their applications and OS during patching.
+  * **The application (DevOps) teams** define the patch groups for their servers based on application environment, OS type, or other criteria. They also define the maintenance windows specific to each patch group. This information should be stored on tags attached to the instances. Recommended tag names are `PatchGroup` and `MaintenanceWindow`. During each patch cycle, the application teams prepare for patching, test the application after patching, and troubleshoot any issues with their applications and OS during patching.
+
+###### Note
+
+Don't use spaces or other whitespace in a tag key. If you enable Instance Metadata Service (IMDS) tags on an instance, a tag key that contains whitespace fails validation. The instance then drops the tag and misses its scheduled patch events.