# Error: Build 'amazon-ebs' errored: Error creating temporary keypair: UnauthorizedOperation

## TL;DR
Your IAM identity may not create EC2 keypairs, so Packer's temporary keypair fails. Either grant `ec2:CreateKeyPair` (and delete) or bring your own key with `ssh_private_key_file` and `ssh_keypair_name`.

## The error

```
Build 'amazon-ebs' errored: Error creating temporary keypair: retry count exhausted. Last err: UnauthorizedOperation: You are not authorized to perform this operation.
```

## Fix it

1. Confirm the IAM gap: the error names `UnauthorizedOperation` on keypair creation, not a network issue.
   - Success check: the failing API call is `CreateKeyPair`.
2. Option A (preferred where allowed): grant the build role `ec2:CreateKeyPair`, `ec2:DeleteKeyPair`, and `ec2:DescribeKeyPairs`.
   - Success check: `aws ec2 create-key-pair --key-name test` works for the build identity.
3. Option B (locked-down accounts): create a keypair yourself, then set `ssh_private_key_file` to your private key and `ssh_keypair_name` to the AWS keypair name so Packer skips temporary creation.
   - Success check: the log no longer shows `Creating temporary keypair`.
4. Re-run the build.
   - Success check: the instance launches and SSH connects.

## When to use this
You hit this in AWS accounts with restrictive IAM where Packer cannot manage keypairs.

## When NOT to use this
Do not use this for SSH *authentication* failures after the instance is up. This error happens before the instance exists.

## Compatibility
Packer 1.x, amazon-ebs and related EC2 builders.

## Variants
- The same `UnauthorizedOperation` when the session-manager path is used and Packer still tries key operations
- `Error creating temporary keypair` with other AWS API denials (read the `Last err`)

## Root cause
By default Packer generates a temporary keypair per build for SSH access. Accounts that forbid `ec2:CreateKeyPair` break this step immediately.

## Edge cases
- With `ssh_interface = "session_manager"` you may still need keypair rights unless fully switched to SSM. Test the exact communicator path you use.
- Remember to also allow `ec2:DeleteKeyPair` or temporary keys accumulate.
