Review EC2 metadata service version settings

Require IMDSv2 when the metadata service is needed.

Description

Allowing IMDSv1 can make instance metadata or temporary credentials easier to reach through some SSRF vulnerabilities. IMDSv2 requires a session token and provides additional protection.

Potential impact

Combined with an application vulnerability, this can expose metadata or instance-role credentials.

Remediation

Set MetadataOptions.HttpTokens to required when the metadata service is needed, and verify application compatibility. If the service is unnecessary, its endpoint can be disabled.

Examples

When explicit options are absent, actual behavior depends on AMI and account defaults. These examples require IMDSv2 on an instance and launch template; choose AmiId and the hop limit for the environment.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: Metadata option comparison

Resources:
  MyEC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: !Ref AmiId
      InstanceType: t3.micro

  MyLaunchTemplate:
    Type: AWS::EC2::LaunchTemplate
    Properties:
      LaunchTemplateName: MySecureLaunchTemplate
      LaunchTemplateData:
        ImageId: !Ref AmiId
        InstanceType: t3.micro

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: Metadata option comparison

Resources:
  MyEC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: !Ref AmiId
      InstanceType: t3.micro
      MetadataOptions:
        HttpEndpoint: enabled
        HttpTokens: required
        HttpPutResponseHopLimit: 2
        HttpProtocolIpv6: disabled

  MyLaunchTemplate:
    Type: AWS::EC2::LaunchTemplate
    Properties:
      LaunchTemplateName: MySecureLaunchTemplate
      LaunchTemplateData:
        ImageId: !Ref AmiId
        InstanceType: t3.micro
        MetadataOptions:
          HttpEndpoint: enabled
          HttpTokens: required
          HttpPutResponseHopLimit: 2
          HttpProtocolIpv6: disabled

References