4 ms·
You can use iptables to allow access only from the root user. That is what we do. I feel like that help to a large degree, assuming you properly run the appli
by gray_-_wolf 3y ago
You can use iptables to allow access only from the root user. That is what we do. I feel like that help to a large degree, assuming you properly run the applications under separate users.
- cedws 3y agoI mention this in my blog post. You can do this, but then you're forced to run all apps that require the IMDS under that specific user. It's better than having no restrictions at all, but having a user shared between multiple apps is also problematic in itself.
- gray_-_wolf 3y agoNot really. You can have a daemon, that fetches from IMDS just what the particular user needs and stores it in a way accessible to just that user.
- cedws 3y agoWell yes, you can do that, but it won't be compatible with the cloud SDKs so you'd have to write your own code to fetch that stuff, as well as implement your own token renewal since IMDS credentials expire fairly quickly. This is easier said than done on a brownfield estate.
- gray_-_wolf 3y ago> Well yes, you can do that, but it won't be compatible with the cloud SDKs I am confused why you just could not use the AWS_WEB_IDENTITY_TOKEN_FILE. You could just produce that file for every user, refresh it before expiration and set the environment variable for each user. I believe that should work with the default SDK just fine, no? I mean, sure, it is not exactly zero effort, but still seems fairly doable...
- cedws 3y agoI have only had a brief look but seems you would also need to specify the role ARN at least, so it would not be as simple as IMDS-sourced credentials. This solution is also AWS-specific, not sure how it would be solved for Google Cloud. It doesn't solve the issue of getting regular metadata without sidestepping the SDKs.
- zokier 3y agoNot really, afaik you can just route requests transparently to your intercepting proxy to do access control. See http://www.daemonology.net/blog/2020-01-27-Announcing-imds-filterd.html http://www.daemonology.net/blog/2020-01-27-Announcing-imds-f... as an example.
- cedws 3y agoI also mention imds-filterd in the post I linked... it has no port to Linux because it uses a FreeBSD feature.