ScaleSec/terraform_aws_scp

Research ec2:Metadata* Conditions for security controls

jdyke opened this issue · 0 comments

jdyke commented

With the new metadata service (v2) there are also new conditions which could potentially be leveraged in SCPs for security controls and guardrails

ec2:MetadataHttpEndpoint
ec2:MetadataHttpPutResponseHopLimit
ec2:MetadataHttpTokens