I'm working in a team with 8 people. I need to create an EC2 intance. Just before I create the instance, EC2 lets me create a key-pair and then download it.
The problem is: That way I need to share the same private key for all 8 team members.
Now, what happens if tomorrow one of the teammates leave? I will need to recreate the machine with a new key pair.
How can I manage the keys correctly so every team member will have his/her unique key that is associate with his/her IAM user, so once he/she leaves the company, I will be able to invalidate his/her key?
Try to avoid giving the PEMs for the instances to everyone, keep these with the Administrators in a tool such as a password vault.
Remember that to rotate these PEMs you would need to manually replace the authorized_keys on any Linux instance, and for Windows instances where you use this PEM to get the Windows password you would need to replace and launch with the new PEM.
AWS has a couple of solutions that help make secure access to your Linux instances easier:
I suggest looking into using EC2 Instance Connect which uses temporary SSH keys and allows you to grant access using IAM policies.
Otherwise, I suggest using a tool like Ansible to manage the SSH keys on your fleet of instances so you can easily add or remove keys.
Your question is not about Ec2 per se, but about the access control model you want to implement.
If all those 8 people need to have identified and individual access to the instance, the simplest way is to create 8 different users at the instance. Each one with a different ssh-key.
It can be done logging into the instance, using the key created for the ec2-user or ubuntu user, then creating each of the users and distributing.
If all you need is one different key for everyone to login into the same user, just ask people to create ssh-keys and share the public key with you. Then you put all of them into the default user .ssh folder.
When someone goes out, simply delete the ssh-key. You can even keep their user for historical reasons.
If the number of instances go up, you should invest into a centralized login management tool like LDAP