Description
When the metadata endpoint is enabled and metadata_options.http_tokens is optional, both IMDSv1 and IMDSv2 requests are allowed. IMDSv2 requires a session token and reduces metadata exposure through some SSRF paths and similar mechanisms. It does not prevent every SSRF attack or instance compromise.
Potential impact
- A vulnerable application can expose metadata or temporary credentials for the instance role.
- Requiring IMDSv2 without checking compatibility can prevent older clients from reading metadata.
Remediation
- If metadata is needed, set http_tokens: required and verify the SDKs, agents and containers that use it. If the endpoint is unnecessary, consider http_endpoint: disabled.
- Check both the effective instance settings and launch settings for new instances. Maintain least-privilege instance roles and SSRF defenses separately.
Examples
Supply real subnet and AMI IDs for the relevant Region through ec2_subnet_id and ec2_image_id. The examples compare instances that need metadata access.
Before
yaml
- name: Create an EC2 instance
amazon.aws.ec2_instance:
name: public-metadataoptions-instance
vpc_subnet_id: "{{ ec2_subnet_id }}"
instance_type: t3.small
image_id: "{{ ec2_image_id }}"
metadata_options:
http_tokens: optional
After
yaml
- name: Create an EC2 instance
amazon.aws.ec2_instance:
name: public-metadataoptions-instance
vpc_subnet_id: "{{ ec2_subnet_id }}"
instance_type: t3.small
image_id: "{{ ec2_image_id }}"
metadata_options:
http_endpoint: enabled
http_tokens: required
Explanation:
- Before: On an enabled endpoint, optional also permits tokenless IMDSv1 requests.
- After: The endpoint is enabled with required to require IMDSv2 tokens.