4 ms·
There is a local metadata API for Azure but it is fairly simple right now. Some limited instance info about your host ID, fault domain, and update domain: curl
by mdeeks 10y ago
There is a local metadata API for Azure but it is fairly simple right now.
Some limited instance info about your host ID, fault domain, and update domain:
curl http://169.254.169.254/metadata/v1/InstanceInfo http://169.254.169.254/metadata/v1/InstanceInfo
Poll this regularly to find out when your VM is about to go down for maintenance:
http://169.254.169.254/metadata/v1/maintenance http://169.254.169.254/metadata/v1/maintenance
Those are the only two endpoints I know of. I encouraged them to require a special header for access to this API before releasing to the public but it looks like it was not included. A special header would help prevent your app from being able to access this from a user specified URL.
Google requires a header to help prevent this: https://cloud.google.com/compute/docs/storing-retrieving-metadata#querying https://cloud.google.com/compute/docs/storing-retrieving-met...
- novaleaf 10y agothank you so much for posting these extra details. My product is hosted on Google Cloud and allows users to arbitrarily craft http requests (including headers!) I try to limit the possibility of abuse (restricting protocol to http, https, //, data, or ftp) but didnt know about this metadata issue. I updated my product to account for this issue too. it looks like google's metadata doesn't leak any important secrets (unless I had custom metadata, which i do not) but better safe than sorry!