Repository navigation
security: harden AWS Windows bake credentials (encrypted WinRM, no GetPasswordData) - #2533
Open
Brad-Edwards wants to merge 2 commits into
Open
Brad-Edwards wants to merge 2 commits into
Brad-Edwards wants to merge 2 commits into
Conversation
…ws bakes The AWS windows, dc and dc-prebaked templates enabled WinRM Basic auth over unencrypted HTTP, and Packer's temporary security group opened the WinRM port to 0.0.0.0/0, so each bake sent the Administrator password across the internet in clear. The builders now bind a self-signed HTTPS listener, drop the plaintext listener, keep AllowUnencrypted off, and admit WinRM only from the builder's public IP. This matches the GCE templates' TLS-only WinRM.
…om EC2 The AWS windows, dc and dc-prebaked bakes let Packer fetch the AMI's generated Administrator password with ec2:GetPasswordData, polling until it appeared. Security monitoring flags those calls. Each builder's user data now sets the built-in Administrator password to a per-build winrm_bootstrap_password before WinRM starts, and Packer connects and elevates with it, so GetPasswordData is never called. A Windows build without the secret fails validation instead of falling back. The AMI build workflow generates the secret for Windows builds before validation, as the GCE workflow already does.
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



The AWS
windows,dcanddc-prebakedPacker templates enabled WinRM Basic auth over unencrypted HTTP (AllowUnencrypted=true), and Packer's temporary security group opened the WinRM port to0.0.0.0/0. Every Windows bake therefore sent the instance's Administrator password across the internet in clear while the port was open to anyone.Each builder's user data now creates a self-signed HTTPS listener, removes the plaintext listener that
winrm quickconfigcreates, and keepsAllowUnencryptedoff. Packer connects withwinrm_use_ssl = true, andtemporary_security_group_source_public_ip = truelimits the temporary group to the builder's public IP. This matches the GCE templates, which already use TLS-only WinRM.A regression test asserts the three templates stay TLS-only and source-restricted.
Verification
tests/test_packer.pypasses (114) andpacker validate -var-file=dev.pkrvars.hcl .is clean.dc-prebakedbake in aws-dev connected over WinRM HTTPS from the operator IP only, promoted the forest across the reboot, ranfinalize.ps1and registered the AMI.windowsanddccarry the identical change but have not been rebaked; they are covered by Windows and DC images still bake Claude Code #2521.No ec2:GetPasswordData
Packer fetched each Windows builder's generated Administrator password by polling
ec2:GetPasswordData, which tripped security monitoring. The builder's user data now sets the built-in Administrator password to a per-buildwinrm_bootstrap_passwordbefore WinRM starts, and Packer connects and elevates with it, so the call is never made. A Windows build without the secret failspacker validateinstead of falling back to the call; Linux builds do not need it.packer.ymlgenerates the secret (masked, viaGITHUB_ENV) forwindows,dcanddc-prebakedbefore validation, aspacker-gcp.ymlalready does for GCE.