Azure / AKS

Azure Kubernetes Service
https://azure.github.io/AKS/
1.95k stars 305 forks source link

Instance Metadata endpoint Restriction #2823

Closed miwithro closed 2 days ago

miwithro commented 2 years ago

Enable a Feature to allow customers to prevent unprivileged pods from accessing HostNetwork which provides access to the IMDS endpoint.

ghost commented 2 years ago

Action required from @Azure/aks-pm

ghost commented 2 years ago

Action required from @Azure/aks-pm

ghost commented 2 years ago

Action required from @Azure/aks-pm

ghost commented 1 year ago

Action required from @Azure/aks-pm

ghost commented 1 year ago

Issue needing attention of @Azure/aks-leads

ghost commented 1 year ago

Action required from @Azure/aks-pm

ghost commented 1 year ago

Issue needing attention of @Azure/aks-leads

ghost commented 1 year ago

Issue needing attention of @Azure/aks-leads

ghost commented 1 year ago

Issue needing attention of @Azure/aks-leads

ghost commented 1 year ago

Issue needing attention of @Azure/aks-leads

ghost commented 1 year ago

Action required from @Azure/aks-pm

ghost commented 1 year ago

Issue needing attention of @Azure/aks-leads

ghost commented 1 year ago

Action required from @Azure/aks-pm

mieky commented 1 year ago

The documented instructions for IMDS hardening were proven problematic to achieve by manual means (on Azure CNI at least), as azure-npm doesn't cope well with introducing a large number of NetworkPolicy objects at once.

I wish there was a recommended way of achieving this, especially for someone using Azure CNI.

ghost commented 1 year ago

Action required from @Azure/aks-pm

microsoft-github-policy-service[bot] commented 7 months ago

This issue has been automatically marked as stale because it has not had any activity for 60 days. It will be closed if no further activity occurs within 15 days of this comment.

microsoft-github-policy-service[bot] commented 7 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 7 months ago

This issue will now be closed because it hasn't had any activity for 7 days after stale. miwithro feel free to comment again on the next 7 days to reopen or open a new issue after that time if you still have a question/issue or suggestion.

microsoft-github-policy-service[bot] commented 1 month ago

@miwithrow, @CocoWang-wql would you be able to assist?

palma21 commented 2 days ago

Closing as duplicate of #4037