cds-snc / notification-planning-core

Project planning for GC Notify Core Team
0 stars 0 forks source link

Use IMDSv2 for all nodes (ie both on demand and spot) #243

Open sastels opened 6 months ago

sastels commented 6 months ago

Description

As a Notify dev, I need Notify to be secure

WHY are we building?

IMDSv1 will soon not be supported by AWS (mid 2024) and is not as secure as IMDSv2

WHAT are we building?

Use IMDSv2 on all nodes

VALUE created by our solution

Security, and also if we don't AWS will randomly do it for us.

Acceptance Criteria

Given some context, when (X) action occurs, then (Y) outcome is achieved.

QA Steps

Additional Information

Incident: celery pod errors