AWS 379: EC2 Image Builder components, tests, distribution, and lifecycle
Why this lesson matters
EC2 Image Builder turns a base AMI or container image, versioned recipe, components, infrastructure, workflows, tests, scans, and distribution rules into governed images. The output is safe only when its provenance, launch behavior, vulnerabilities, sharing, downstream use, and retirement are verified.
Image pipeline model
| Construct | Purpose | Evidence |
|---|---|---|
| Base image | Trusted starting operating system | Publisher, exact AMI/digest, age |
| Recipe | Versioned base plus ordered components | Recipe ARN/version and dependencies |
| Component | Build/validate/test document | Source hash, parameters, logs/results |
| Infrastructure configuration | Build/test instance, role, network, logs | Subnet/SG/profile and cleanup |
| Workflow | Build, test, distribution steps/control | Step outcome, timeout, rollback behavior |
| Distribution configuration | Region/account/OU and launch settings | Resulting AMI IDs/digests/permissions |
| Lifecycle policy | Deprecate, disable, delete by policy | Execution/resource result and exclusions |
Build runs components against the base, validates customization, and creates an intermediate image. Test launches that image and runs independent test components and optional scan collection. Distribution copies/shares/configures approved output. A package-install command succeeding is not enough: reboot, service enablement, filesystem state, IMDS settings, encryption, agent health, patch baseline, architecture, and application smoke tests matter.
Pin component and recipe semantic versions. Record source commit, component document hash, base AMI/digest, package repositories and versions, build instance, output AMI/snapshot or container digest, scan/SBOM, tests, account, Region, KMS key, and distribution. Mutable package repositories can make identical recipe versions produce different bytes; decide whether freshness or reproducibility governs and retain the resolution evidence.
Schedule rebuilds for patch freshness, but also trigger from approved base/component changes and urgent vulnerability response. Prevent overlapping executions from racing promotion. Publish an event when build, test, distribution, scan, or lifecycle fails; route it to an accountable image team. Define maximum image age and block downstream promotion when provenance, tests, or regional distribution are incomplete.
Security, networking, and distribution
The service-linked role, infrastructure instance profile, workflow role, lifecycle role, and cross-account distribution roles have different trust. Apply least privilege. Build instances can execute supplied code, so isolate subnets/security groups, restrict egress and endpoints, use encrypted temporary/output storage, protect logs, block inbound access, and prevent secret baking. Use temporary retrieval and remove credentials/history/cache before image creation.
Distribution creates new regional AMIs/snapshots or ECR copies and may change launch permissions. KMS key policies/grants must allow target copy/use. Sharing an encrypted AMI requires usable encrypted snapshots and target authorization. Verify target account launch and runtime, not just copy status. Track every regional AMI ID back to one Image Builder image version.
Lifecycle and downstream safety
Lifecycle policies can deprecate, disable, and delete eligible image resources; associated AMIs, snapshots, regional copies, or ECR images change only when configured. One applicable action is performed per evaluation in priority order, and cancellation does not reverse completed actions. Exclusions may use tags, launch recency, public/shared state, or Region, with documented timing limits.
Image Builder does not prove an image is unused by launch templates, Auto Scaling groups, instance refresh rollback, disaster recovery, or external accounts. Maintain a consumer inventory and minimum known-good generations. Deprecate first, stop new references, validate replacement, disable, wait through rollback/DR windows, then deregister/delete snapshots. Key deletion and cleanup can make retained images unusable.
Read-only inspection and workshop
aws imagebuilder list-image-pipelines --region ap-south-1
aws imagebuilder get-image-pipeline --image-pipeline-arn PIPELINE_ARN --region ap-south-1
aws imagebuilder get-image --image-build-version-arn IMAGE_ARN --region ap-south-1
aws imagebuilder list-image-build-versions --image-version-arn VERSION_ARN --region ap-south-1
aws imagebuilder list-lifecycle-policies --region ap-south-1
aws ec2 describe-images --image-ids AMI_ID --region ap-south-1
Design a RHEL-compatible web-server image factory across two Regions and two accounts. Define base trust, patch/component order, validation, reboot, functional/security tests, Inspector/SBOM decision, infrastructure isolation, event/metric/log evidence, KMS/distribution roles, launch verification, promotion, and 30/60/120-day lifecycle with protected generations.
Inject 16 failures: base revoked, repository unavailable, component non-idempotent, reboot lost state, disk full, wrong architecture, instance-profile deny, no egress/endpoint, test false positive, critical finding, KMS copy deny, target launch deny, regional copy partial failure, mutable package result, lifecycle excludes wrong image, and deletion breaks rollback. State detection, abort/quarantine, evidence, repair, and consumer effect.
Cost and acceptance
Image Builder service use may not add a direct charge, but EC2 build/test time, EBS/snapshots, S3, ECR/scanning, Inspector, KMS, logs, data transfer, copied images, and retained generations do. This lesson creates nothing.
Submit pipeline/data-flow diagram, trust map, provenance manifest, component/test plan, distribution/KMS matrix, consumer registry, lifecycle transition table, sixteen failures, cost forecast, and recovery. Pass requires independent launch tests, immutable traceability, no baked secret, bounded sharing, and no deletion based only on image age.