You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Which service is this feature request for?
Red Hat OpenShift Service on AWS HCP
What are you trying to do?
As Amazon Security hub recommends - EC2 instances should use Instance Metadata Service Version 2 (IMDSv2), When I tried to create ROSA HCP cluster with --ec2-metadata-http-tokens required, it resulted in an error showing --ec2-metadata-http-tokens is not available for ROSA HCP
Which service is this feature request for?
Red Hat OpenShift Service on AWS HCP
What are you trying to do?
As Amazon Security hub recommends - EC2 instances should use Instance Metadata Service Version 2 (IMDSv2), When I tried to create ROSA HCP cluster with
--ec2-metadata-http-tokens required
, it resulted in an error showing --ec2-metadata-http-tokens is not available for ROSA HCPNote that Amazon EKS supports IMDSV2 from 2020 and reasoning behind IMDSV2 support here - https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service/
Describe the solution you'd like
Refer this screenshot showing all EC2 instances created with IMDSV2 -
Optional
. , we want to seeRequired
Describe alternatives you've considered
None available
Additional context
Amazon Security has documented https://aws.amazon.com/blogs/security/get-the-full-benefits-of-imdsv2-and-disable-imdsv1-across-your-aws-infrastructure/
The text was updated successfully, but these errors were encountered: