
I tried out the new "shared tags" feature for Amazon EC2 AMIs
This page has been translated by machine translation. View original
Introduction
On 2026-10-05, AMI shared tags were added for Amazon EC2.
This feature allows tags set by the AMI owner with the prefix ec2:SharedTag/ in the key to be visible from the accounts the AMI is shared with. It is available in all regions at no additional cost.
This article presents the results of sharing an AMI with another account and testing how tags appear from the recipient's side, as well as how updates made by the owner are reflected.
AMI Shared Tag Specifications
The specifications can be found on the following pages in the EC2 User Guide.
Tags with the ec2:SharedTag/ prefix in the key are visible to recipients not only when sharing with a specified account, but also when sharing via AWS Organizations or public sharing.
Verification Setup
Two accounts were used: a sharing source and a sharing destination. The region was ap-northeast-1. The latest Amazon Linux 2023 (x86_64) AMI was copied to the source account, and it was shared with the destination account specified. The source AMI ID was obtained using the SSM parameter /aws/service/ami-amazon-linux-latest/al2023-ami-kernel-default-x86_64.
The tags status and os-version with the ec2:SharedTag/ prefix were set as shared tags. A tag with the key team was also added to confirm it would not be visible to the destination account.
aws ec2 create-tags \
--resources ami-0abcdef1234567890 \
--tags \
Key=ec2:SharedTag/status,Value=approved \
Key=ec2:SharedTag/os-version,Value=2023.12.20260930.0 \
Key=team,Value=private-only
The AMI was shared with the destination account.
aws ec2 modify-image-attribute \
--image-id ami-0abcdef1234567890 \
--launch-permission "Add=[{UserId=<destination account ID>}]"
Tags Visible from the Destination Account
The following are the results of running describe-images with the AMI ID specified from the destination account.
| Tag Key | Value set by source | Tags in destination's describe-images |
|---|---|---|
| ec2:SharedTag/status | approved | approved |
| ec2:SharedTag/os-version | 2023.12.20260930.0 | 2023.12.20260930.0 |
| team | private-only | Not included |
The shared AMI could be referenced by specifying only the AMI ID, and adding --executable-users self yielded the same result. Combining --executable-users self with --filters Name=tag-key,Values=ec2:SharedTag/* also returned the same AMI.
Modification and Deletion from the Destination Account
From the destination account, attempts were made to overwrite the value of the shared tag status with hacked, delete the same tag, and create a new shared tag. All three were denied with AccessDenied. Both the overwrite and the new creation used the CreateTags call and returned the same message. The messages for CreateTags and DeleteTags are as follows.
An error occurred (AccessDenied) when calling the CreateTags operation: Only the resource owner can create shared tags on resource 'ami-0abcdef1234567890'.
An error occurred (AccessDenied) when calling the DeleteTags operation: Only the resource owner can delete shared tags on resource 'ami-0abcdef1234567890'.
On the other hand, tags without the ec2:SharedTag/ prefix in the key could be created from the destination account as well.
Reflection of Updates Made by the Source Account
From the source account, the value of the shared tag status was updated from approved to deprecated.
Approximately 5 seconds after the update, running describe-images from the destination account showed that the value of status had changed to deprecated. The following is the output with only the Tags extracted from the result.
[
[
{
"Key": "ec2:SharedTag/status",
"Value": "deprecated"
},
{
"Key": "ec2:SharedTag/os-version",
"Value": "2023.12.20260930.0"
}
]
]
Summary
It was confirmed that among AMI tags, those with the ec2:SharedTag/ prefix in the key become readable from the destination accounts and that updates made by the source account are also reflected in the destination accounts.
As introduced in the AWS Compute Blog, when deprecating older AMIs in a golden AMI operation where a build account distributes approved AMIs to many accounts, change the value of the shared tag status to deprecated in the source account. In the destination accounts, referring to the propagated shared tag status allows users to avoid using deprecated AMIs.
If you have had challenges managing tags for shared AMIs until now, please try out this update.
