Review IMDSv1 access to EC2 metadata

Require IMDSv2 for needed metadata access and verify the effective configuration.

Description

IMDSv1 accesses instance metadata without a session token and can be abused through attacks such as SSRF. When the metadata endpoint is enabled, http_tokens = "optional" also permits IMDSv1. Omitted options are affected by account and AMI settings, so verify the effective values.

Potential impact

  • A vulnerable application can expose metadata or temporary role credentials.
  • Stolen credentials can be abused within the instance profile’s permissions.

Remediation

Check SDK, bootstrap-script, and container compatibility, then set http_tokens = "required" for metadata access that is needed. Consider disabling the endpoint if metadata is unnecessary. Also fix SSRF vulnerabilities and minimize role permissions; IMDSv2 is an additional protection.

Examples

These excerpts compare metadata options. Replace the AMI with one valid in the target Region, and review launch-template and Auto Scaling settings as well.

Before

hcl
resource "aws_instance" "example" {
  ami           = "ami-12345678"
  instance_type = "t2.micro"

  metadata_options {
    http_tokens = "optional"
  }
}

After

hcl
resource "aws_instance" "example" {
  ami           = "ami-12345678"
  instance_type = "t2.micro"

  metadata_options {
    http_endpoint = "enabled"
    http_tokens   = "required"
  }
}

The first setting allows IMDSv1 when the endpoint is enabled. The second enables the endpoint and requires an IMDSv2 token. This change alone does not prevent every SSRF attack.

References