VectleSkillsError: Build 'amazon-ebs' errored: Error creating temporary keypair

Error: Build 'amazon-ebs' errored: Error creating temporary keypair

Export

Fixes Packer failing to create its temporary SSH keypair due to IAM permissions. For engineers in locked-down AWS accounts where keypair creation is denied, with the bring-your-own-key workaround.

Error: Build 'amazon-ebs' errored: Error creating temporary keypair: UnauthorizedOperation

TL;DR

Your IAM identity may not create EC2 keypairs, so Packer's temporary keypair fails. Either grant ec2:CreateKeyPair (and delete) or bring your own key with ssh_private_key_file and ssh_keypair_name.

The error

Build 'amazon-ebs' errored: Error creating temporary keypair: retry count exhausted. Last err: UnauthorizedOperation: You are not authorized to perform this operation.

Fix it

  1. Confirm the IAM gap: the error names UnauthorizedOperation on keypair creation, not a network issue.
  • Success check: the failing API call is CreateKeyPair.
  1. Option A (preferred where allowed): grant the build role ec2:CreateKeyPair, ec2:DeleteKeyPair, and ec2:DescribeKeyPairs.
  • Success check: aws ec2 create-key-pair --key-name test works for the build identity.
  1. Option B (locked-down accounts): create a keypair yourself, then set ssh_private_key_file to your private key and ssh_keypair_name to the AWS keypair name so Packer skips temporary creation.
  • Success check: the log no longer shows Creating temporary keypair.
  1. Re-run the build.
  • Success check: the instance launches and SSH connects.

When to use this

You hit this in AWS accounts with restrictive IAM where Packer cannot manage keypairs.

When NOT to use this

Do not use this for SSH authentication failures after the instance is up. This error happens before the instance exists.

Compatibility

Packer 1.x, amazon-ebs and related EC2 builders.

Variants

  • The same UnauthorizedOperation when the session-manager path is used and Packer still tries key operations
  • Error creating temporary keypair with other AWS API denials (read the Last err)

Root cause

By default Packer generates a temporary keypair per build for SSH access. Accounts that forbid ec2:CreateKeyPair break this step immediately.

Edge cases

  • With ssh_interface = "session_manager" you may still need keypair rights unless fully switched to SSM. Test the exact communicator path you use.
  • Remember to also allow ec2:DeleteKeyPair or temporary keys accumulate.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Error%3A+Build+%27amazon-ebs%27+errored%3A+Error+creating+temporary+keypair&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.