Merged
Conversation
It was discovered that some customers' EKS clusters did not have their IMDSv2 hop limits set correctly, causing requests for key functionality to attempt IMDSv1 fallback and failing. For now, re-enable IMDSv1 fallback by way of removing the explicit disabling of `EC2MetadataEnableFallback` until better documentation, error handling, and other work can be done to inform customers that they need to correctly set their IMDSv2 hop limits.
1b80978 to
6e6c6d5
Compare
espadolini
approved these changes
Mar 14, 2024
Contributor
espadolini
left a comment
There was a problem hiding this comment.
Perhaps in the changelog we could mention the possibility of setting the AWS_EC2_METADATA_V1_DISABLED envvar to still preclude the fallback to IMDSv1.
Contributor
Author
Thanks. Added! |
hugoShaka
approved these changes
Mar 14, 2024
|
@reedloden See the table below for backport results.
|
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
It was discovered that some customers' EKS clusters did not have their IMDSv2 hop limits set correctly (specifically, set to
1instead of2), causing requests for key functionality to attempt IMDSv1 fallback and failing.For now, re-enable IMDSv1 fallback by way of removing the explicit disabling of
EC2MetadataEnableFallbackuntil better documentation, error handling, and other work can be done to inform customers that they need to correctly set their IMDSv2 hop limits.This is a partial revert of #34170.
changelog: Re-enable AWS IMDSv1 fallback due to some EKS clusters having their IMDSv2 hop limit set to
1, leading to IMDSv2 requests failing. Users who wish to keep IMDSv1 fallback disabled can set theAWS_EC2_METADATA_V1_DISABLEDenvironmental variable.