EC2 메타데이터 서비스 버전 설정 점검

메타데이터 서비스가 필요하면 IMDSv2를 요구하세요.

설명

IMDSv1을 허용하면 일부 SSRF 취약점을 통해 인스턴스 메타데이터나 임시 자격 증명에 접근하기 쉬워질 수 있습니다. IMDSv2는 세션 토큰을 요구해 추가 보호를 제공합니다.

잠재적 영향

애플리케이션 취약점과 결합하면 메타데이터나 인스턴스 역할의 자격 증명이 노출될 수 있습니다.

해결 방법

메타데이터 서비스가 필요하면 MetadataOptions.HttpTokens를 required로 설정하고 애플리케이션 호환성을 확인하세요. 서비스가 불필요한 경우에는 엔드포인트를 비활성화할 수 있습니다.

예시

명시적 옵션이 없는 경우의 실제 동작은 AMI와 계정 기본값에 따라 달라집니다. 예시는 인스턴스와 시작 템플릿에 IMDSv2를 명시하며, AmiId와 홉 제한은 환경에 맞게 지정해야 합니다.

변경 전

yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: 메타데이터 옵션 비교 예시

Resources:
  MyEC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: !Ref AmiId
      InstanceType: t3.micro

  MyLaunchTemplate:
    Type: AWS::EC2::LaunchTemplate
    Properties:
      LaunchTemplateName: MySecureLaunchTemplate
      LaunchTemplateData:
        ImageId: !Ref AmiId
        InstanceType: t3.micro

변경 후

yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: 메타데이터 옵션 비교 예시

Resources:
  MyEC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: !Ref AmiId
      InstanceType: t3.micro
      MetadataOptions:
        HttpEndpoint: enabled
        HttpTokens: required
        HttpPutResponseHopLimit: 2
        HttpProtocolIpv6: disabled

  MyLaunchTemplate:
    Type: AWS::EC2::LaunchTemplate
    Properties:
      LaunchTemplateName: MySecureLaunchTemplate
      LaunchTemplateData:
        ImageId: !Ref AmiId
        InstanceType: t3.micro
        MetadataOptions:
          HttpEndpoint: enabled
          HttpTokens: required
          HttpPutResponseHopLimit: 2
          HttpProtocolIpv6: disabled

참조