Amazon EC2 announces AMI Watermarks for improved AMI governance

Amazon EC2 AMI Watermarks
Amazon EC2 now supports AMI watermarks, allowing you to embed custom identifiers in your private AMIs. These watermarks carry forward to every derived AMI, across regions or instances, and remain visible when shared with other accounts. This feature helps identify trusted AMIs, track provenance, and enforce governance policies.
Each watermark includes metadata such as AMI ID, owner ID, region, and creation timestamps, ensuring reliable provenance. You can filter and find related AMIs across accounts and restrict instance launches to approved watermarks using Declarative Policies.
What to do
- Add watermarks to your private AMIs using the AWS Management Console, AWS CLI, or SDKs.
- Use EC2 Image Builder to attach watermarks as part of your AMI build pipeline.
AMI watermarks are available at no additional cost in all AWS regions, including AWS China and AWS GovCloud (US) Regions.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



