Details
-
Improvement
-
Status: Resolved
-
Normal
-
Resolution: Fixed
-
FACT 2.5.1, FACT 3.14.1
-
Night's Watch
-
3
-
NW - 2021-09-08
-
45595
-
1
-
Enhancement
-
-
Needs Assessment
Description
The AWS IDMSv2 is a super important security feature offered on EC2 instances.
FACT-2306 had recently added facter support for it.
I would very like to port this into facter 2.x and 3.x. Is there a possibility a new patch version for those majors would be released if I port the IDMSv2 support?
Amazon recently released version 2 of their instance metadata service. The new service is session-oriented rather than a simple request/response HTTP call, and was created in response to recent security breaches.
Facter currently only seems to support version 1 of the metadata service for the ec2_metadata and ec2_userdata facts, making it difficult for Puppet users in high-security environments to transition to version 2 of the service.
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html