Uploaded image for project: 'Facter'
  1. Facter
  2. FACT-2306

Add support for AWS IMDSv2

    XMLWordPrintable

Details

    • Night's Watch
    • 3
    • ghost-11.11, ghost 25.11, ghost-2.12, ghost-9.12
    • New Feature
    • Hide
      Updated EC2 fact to be able to use IMDSv2 to authenticate. To use v2, you need to set AWS_IMDSv2 environment variable to true.
      Note: the token is cached for a maximum of 100 seconds.
      Show
      Updated EC2 fact to be able to use IMDSv2 to authenticate. To use v2, you need to set AWS_IMDSv2 environment variable to true. Note: the token is cached for a maximum of 100 seconds.
    • Needs Assessment

    Description

      Amazon recently released version 2 of their instance metadata service. The new service is session-oriented rather than a simple request/response HTTP call, and was created in response to recent security breaches.

      Facter currently only seems to support version 1 of the metadata service for the ec2_metadata and ec2_userdata facts, making it difficult for Puppet users in high-security environments to transition to version 2 of the service.

      https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html

      Attachments

        Issue Links

          Activity

            People

              sebastian.miclea Sebastian Miclea
              ragnarkon Bryan Woolsey
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Zendesk Support