Error: Build 'amazon-ebs' errored: Error creating temporary keypair
Fixes Packer failing to create its temporary SSH keypair due to IAM permissions. For engineers in locked-down AWS accounts where keypair creation is denied, with the bring-your-own-key workaround.
Error: Build 'amazon-ebs' errored: Error creating temporary keypair: UnauthorizedOperation
TL;DR
Your IAM identity may not create EC2 keypairs, so Packer's temporary keypair fails. Either grant ec2:CreateKeyPair (and delete) or bring your own key with ssh_private_key_file and ssh_keypair_name.
The error
Build 'amazon-ebs' errored: Error creating temporary keypair: retry count exhausted. Last err: UnauthorizedOperation: You are not authorized to perform this operation.Fix it
- Confirm the IAM gap: the error names
UnauthorizedOperationon keypair creation, not a network issue.
- Success check: the failing API call is
CreateKeyPair.
- Option A (preferred where allowed): grant the build role
ec2:CreateKeyPair,ec2:DeleteKeyPair, andec2:DescribeKeyPairs.
- Success check:
aws ec2 create-key-pair --key-name testworks for the build identity.
- Option B (locked-down accounts): create a keypair yourself, then set
ssh_private_key_fileto your private key andssh_keypair_nameto the AWS keypair name so Packer skips temporary creation.
- Success check: the log no longer shows
Creating temporary keypair.
- Re-run the build.
- Success check: the instance launches and SSH connects.
When to use this
You hit this in AWS accounts with restrictive IAM where Packer cannot manage keypairs.
When NOT to use this
Do not use this for SSH authentication failures after the instance is up. This error happens before the instance exists.
Compatibility
Packer 1.x, amazon-ebs and related EC2 builders.
Variants
- The same
UnauthorizedOperationwhen the session-manager path is used and Packer still tries key operations Error creating temporary keypairwith other AWS API denials (read theLast err)
Root cause
By default Packer generates a temporary keypair per build for SSH access. Accounts that forbid ec2:CreateKeyPair break this step immediately.
Edge cases
- With
ssh_interface = "session_manager"you may still need keypair rights unless fully switched to SSM. Test the exact communicator path you use. - Remember to also allow
ec2:DeleteKeyPairor temporary keys accumulate.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.