Terraform module to provision a fully managed AWS EKS Node Group
91
stars
128
forks
source link
Change validation of put response hop limit to allow `1` as value to limit access to worker node's metadata endpoint #122
Closed
jakubbujny closed 1 year ago
what
metadata_http_put_response_hop_limit
variable to allow to set1
as value.why
metadata_http_tokens_required
and setmetadata_http_put_response_hop_limit
to 1 - see https://aws.github.io/aws-eks-best-practices/security/docs/iam/#restrict-access-to-the-instance-profile-assigned-to-the-worker-node