Auditing Ecs Task Metadata Boundaries

Audit container task credential and metadata boundaries in orchestrated compute such as ECS: a workload that can reach the container credential endpoint or the host instance metadata service to obtain a role broader than the task needs, a task role over-scoped for the workload, a sidecar or co-located container sharing the same credentials, and a server-side request path inside the task that reaches the metadata endpoint. Covers the task credential relative URI, the instance metadata service reachable from a task, and the blast radius when one container in a task is compromised. Use when containerized workloads assume a task or instance role and the metadata endpoints are the boundary. The reachable metadata endpoint is the source, the credential it returns is the sink, and the role wider than the task's need is the bug.

UnboundCompute a1e41b5 9.1 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-ecs-task-metadata-boundaries commit a1e41b5414

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-ecs-task-metadata-boundaries