Review EC2 instance metadata access protection

Require IMDSv2 for necessary metadata access and verify application compatibility.

Description

When the metadata endpoint is enabled and metadata_options.http_tokens is optional, both IMDSv1 and IMDSv2 requests are allowed. IMDSv2 requires a session token and reduces metadata exposure through some SSRF paths and similar mechanisms. It does not prevent every SSRF attack or instance compromise.

Potential impact

  • A vulnerable application can expose metadata or temporary credentials for the instance role.
  • Requiring IMDSv2 without checking compatibility can prevent older clients from reading metadata.

Remediation

  • If metadata is needed, set http_tokens: required and verify the SDKs, agents and containers that use it. If the endpoint is unnecessary, consider http_endpoint: disabled.
  • Check both the effective instance settings and launch settings for new instances. Maintain least-privilege instance roles and SSRF defenses separately.

Examples

Supply real subnet and AMI IDs for the relevant Region through ec2_subnet_id and ec2_image_id. The examples compare instances that need metadata access.

Before

yaml
- name: Create an EC2 instance
  amazon.aws.ec2_instance:
    name: public-metadataoptions-instance
    vpc_subnet_id: "{{ ec2_subnet_id }}"
    instance_type: t3.small
    image_id: "{{ ec2_image_id }}"
    metadata_options:
      http_tokens: optional

After

yaml
- name: Create an EC2 instance
  amazon.aws.ec2_instance:
    name: public-metadataoptions-instance
    vpc_subnet_id: "{{ ec2_subnet_id }}"
    instance_type: t3.small
    image_id: "{{ ec2_image_id }}"
    metadata_options:
      http_endpoint: enabled
      http_tokens: required

Explanation:

  • Before: On an enabled endpoint, optional also permits tokenless IMDSv1 requests.
  • After: The endpoint is enabled with required to require IMDSv2 tokens.

References