aws / aws/graph-explorer

Support IMDSv2-only when deployed to an EC2 instance

Open
#119 1 comment 1 reaction 0 assignees View on GitHub
database support security
Dominant language
TypeScript
Stars
481
Forks
108
Avg merge
8d 9h
Merged PRs (30d)
7

Description

AWS launched support for a more secure instance metadata store (IMDS) back in 2019. Many have asked (in other forums) if graph-explorer supports using only IMDSv2 (disabling IMDSv1) for security purposes. Submitting this issue as a "to do" to ensure that graph-explorer can be used in these situations.

- [IMDSv2 launch blog post](https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service/)

## Related issues

- Duplicate of #652

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points; start by reviewing related issue #652 and the EC2 deployment configuration. Done means graph-explorer can run when IMDSv1 is disabled and uses IMDSv2-only metadata access.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, typescript
Domain
cloud, infrastructure
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.