Asterrr's Handbook

Compute hardening

Golden AMIs with EC2 Image Builder, hardened container images, IMDSv2, instance profiles vs service and execution roles, Session Manager, EC2 Instance Connect and its endpoint, removing SSH keys, and host-based controls.

Exam tasks: 3.2 (hardened AMIs and container images with Systems Manager and Image Builder; instance profiles, service roles and execution roles; secure administrative access with Session Manager and EC2 Instance Connect)

The decision: what does a workload start with (image), what can it do once running (role and metadata), and how do humans get onto it (access path) without leaving a standing door open?

The hardened image pipeline

EC2 Image Builder and golden AMIs

  • A pipeline runs an image recipe (parent image plus ordered components) or a container recipe on a schedule or when a dependency changes.
  • Components are YAML documents with build, validate and test phases. AWS provides hardening components for CIS benchmarks and DISA STIGs, plus agents such as the CloudWatch agent.
  • Image Builder can run an Inspector scan on the build output and fail the pipeline on findings above a threshold.
  • Distribution settings copy AMIs to other Regions, share them with accounts or OUs, and re-encrypt with a KMS key per Region. Target accounts need kms:Decrypt and kms:CreateGrant on the key in its key policy.
  • Lifecycle policies deprecate and delete old images, so nobody launches a two-year-old AMI.
  • The build instances use an instance profile with EC2InstanceProfileForImageBuilder and AmazonSSMManagedInstanceCore. Image Builder drives them through Systems Manager, so they need no SSH.

Keep people on the golden images:

  • Allowed AMIs (an EC2 account setting, managed by declarative policies in Organizations) restricts which AMI owners or names can be launched.
  • Block public access for AMIs stops accidental public sharing.
  • Treat instances as immutable: fix the image and replace instances rather than patching the fleet by hand. Use Patch Manager for long-lived servers (see Vulnerability and patch management).

Exam signal

"Every new AMI must include the security agent and pass the CIS benchmark before any team can use it, across 20 accounts" is an Image Builder pipeline with hardening and test components, an Inspector scan, and distribution to the OUs. Pair it with Allowed AMIs or an SCP condition on ec2:Owner to make the golden images mandatory.

Hardened container images

  • Start from a minimal base (distroless, Alpine, Bottlerocket for nodes). Fewer packages mean fewer CVEs.
  • Run as a non-root user, drop Linux capabilities, and use a read-only root file system in the task definition or pod spec.
  • Never bake secrets into layers. Every layer is readable by anyone who can pull the image. Inject secrets at run time from Secrets Manager or Parameter Store.
  • Turn on ECR tag immutability so a trusted tag can't be overwritten, and deploy by digest.
  • Sign images (AWS Signer with Notation) and verify signatures at admission in EKS.
  • Scan with Inspector enhanced scanning on push and continuously.

Instance metadata: require IMDSv2

  • IMDSv2 requires a session token obtained with an HTTP PUT. It blocks the classic SSRF attack, where a web app is tricked into fetching 169.254.169.254 credentials through a GET, and open reverse proxies.
  • Set HttpTokens=required on launch templates and existing instances. Make it the account-level default for new instances, and enforce with an SCP on ec2:RunInstances using the ec2:MetadataHttpTokens condition.
  • The hop limit of 1 keeps IMDS responses from reaching containers on the host (AMIs flagged for IMDSv2, such as Amazon Linux 2023, default to 2). Use 2 only when containers legitimately need IMDS. Use 1 on EKS nodes where pods should use Pod Identity instead.
  • Turn IMDS off entirely for instances that don't need it.
  • Detect stolen instance credentials: GuardDuty flags them when they're used from outside AWS or from another account. Limit them with the aws:EC2InstanceSourceVPC and aws:EC2InstanceSourcePrivateIPv4 condition keys.

Giving workloads an identity

MechanismWho assumes itUsed for
Instance profileEC2 instance (container for one role)Software on the instance calling AWS APIs. Credentials rotate through IMDS
Service roleAn AWS service acting in your accountImage Builder, CodeBuild, Config, Systems Manager Automation
Service-linked roleA service, with a policy the service definesPredefined by the service. You can't edit its permissions
Lambda execution roleLambdaEverything the function's code does
ECS task roleContainers in the taskApp calls to S3, DynamoDB and so on
ECS task execution roleThe ECS agentPull from ECR, write logs, fetch secrets for the task definition
EKS Pod Identity / IRSAA Kubernetes service accountPer-pod AWS permissions instead of the node role
  • One role per workload, least privilege, no access keys on disk. Use IAM Access Analyzer policy generation to trim roles from CloudTrail activity (see Least privilege tooling).
  • A user who attaches a role to a resource needs iam:PassRole for that role. Scope it with the iam:PassedToService condition.
  • An instance holds one role at a time. Replace the profile association to change it, and running processes pick up new credentials on the next refresh.

Task role vs task execution role

If containers get AccessDenied calling S3, fix the task role. If the task fails to start because it can't pull the image or read a secret referenced in the task definition, fix the task execution role. Distractors often swap the two.

Administrative access without SSH

Session ManagerEC2 Instance ConnectEC2 Instance Connect Endpoint
Inbound portsNone. The SSM Agent calls out22 from the client (public IP or VPN)22 or 3389 only from the endpoint
AuthIAM (ssm:StartSession), with tag-based conditionsIAM pushes a one-time public key (SendSSHPublicKey), valid 60 secondsIAM (ec2-instance-connect:OpenTunnel), then SSH key or pushed key
Needs on instanceSSM Agent + instance profile or Default Host Management ConfigurationEC2 Instance Connect package (for pushed keys)Nothing extra if you use your own key
Session loggingFull transcript to S3 or CloudWatch Logs, encrypted with KMSOnly the API call in CloudTrailTunnel open in CloudTrail
Private subnetYes, with ssm, ssmmessages, ec2messages VPC endpointsNo, needs a network pathYes, no IGW or bastion needed
  • Session Manager also does port forwarding (for example to an RDS database through an instance) and runs sessions as a configured OS user (Run As).
  • A session preferences document sets logging, KMS encryption of the session stream, idle timeout and shell profile. Deny ssm:StartSession on the default document so users can't bypass it.
  • The EC2 Instance Connect Endpoint is an identity-aware TCP proxy: up to 20 concurrent connections, sessions up to 1 hour, and one endpoint per VPC.

Exam signal

"No inbound ports, no bastion, and every command must be logged" is Session Manager with S3 or CloudWatch Logs session logging. "Engineers must use their normal SSH client to reach private instances without a bastion or public IP" is the EC2 Instance Connect Endpoint.

Removing SSH keys and handling a leaked one

  • Deleting a key pair in the EC2 console doesn't remove it from instances. The public key stays in ~/.ssh/authorized_keys until you remove it.
  • To remove a compromised key across a fleet: use Run Command (or State Manager, to keep it removed) with a script that deletes that key from authorized_keys on every instance, then rotate any other credentials the key holder could reach.
  • Lost the key for a single instance: connect with Session Manager and add a new public key, or use the AWSSupport-ResetAccess automation.
  • Then remove SSH altogether: close port 22 in security groups, move admins to Session Manager, and alert on security groups that open 22 or 3389 to 0.0.0.0/0 with AWS Config.
  • For forensic steps on a compromised host, see Compromised workloads.

Host-based controls

Security groups and NACLs see addresses and ports. On-host controls see processes, files and payloads.

  • Host firewall (iptables, nftables, Windows Defender Firewall) as a second layer, for example blocking IMDS for all users except root.
  • HIDS, antivirus and file integrity monitoring from third parties, deployed and kept running with State Manager associations or Distributor packages.
  • GuardDuty Runtime Monitoring agent for process, file and network events on EC2, ECS and EKS (see Threat detection).
  • CloudWatch agent to ship OS and application logs for detection.
  • EBS encryption by default, and Nitro Enclaves for processing highly sensitive data in isolation.
60 s
How long a key pushed with EC2 Instance Connect stays valid.
1 hour
Maximum tunnel duration through an EC2 Instance Connect Endpoint.
1 hop
IMDS hop limit that keeps containers on the host from reaching metadata. 2 lets them through.
169.254.169.254
Instance metadata address. SSRF target that IMDSv2 protects.

Scenarios

Scenario · choose 2
A penetration tester used a server-side request forgery flaw in a customer portal on EC2 to read http://169.254.169.254/latest/meta-data/iam/security-credentials/ and retrieve role credentials. The company runs 900 instances in 30 accounts and wants to stop this class of attack across the organization, including for instances launched later. Which combination of actions is best? (Choose TWO.)
Scenario
A media company wants to remove all bastion hosts. Administrators must reach Linux instances in private subnets with no internet access, no inbound security group rules may be added, and every command typed must be kept for 1 year, encrypted with a customer managed key. What should the security engineer implement?
Scenario
An ECS on Fargate service fails to start with the error 'unable to retrieve secret from asm' for a database password referenced in the task definition. Once running, the application must also read objects from an S3 bucket. Which change fixes the startup failure while following least privilege?

Further reading

On this page