Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-4551

Support for changing EC2 Instance Metadata Version (IMDS) (day-2) on ROSA/OSD Clusters


    • False
    • None
    • False
    • Not Selected

      1. Proposed title of this feature request

      HIVE support for modifying EC2 Instance Metadata Options

      2. What is the nature and description of the request?

      From the OCP Documentation [1], I understand that self-managed OCP customers can modify (day-2) the EC2 Instance Metadata options. However, Hive's customers like ROSA and OSD on AWS do not have this support. 

      3. Why does the customer need this? (List the business requirements here)

      Motivation for customers to use EC2 IMDS is to increase security posture provided by IMDS v2 endpoint and use AWS governance tools like IAM Policy, SCPs, AWS Configs etc to track compliance. Today, Hive and Hive customers can set this value at the time of cluster creation however, if they need to move between IMDSv2 optional and IMDSv2 required, they can not change this. They'd like to change it on all cluster's EC2 instances - including control plane, infra nodes, and compute nodes. In the Service Delivery, this also includes any temporary instances used for bootstrapping, supporting etc. 

      Today the alternative available are 1) Delete and recreate the cluster 2) SRE do white-glove process to modify this upon customer request. Given OCP documentation has steps to modify this, it is confusing for customers to understand why the managed service does not give a self-service way to have this configuration changed.

      4. List any affected packages or components.

        **  - Hive

      • Machine-API / Machine-Sets

      5. Additional Information:

      Slack Discussion in #forum-ocp-hive : https://redhat-internal.slack.com/archives/CE3ETN3J8/p1691596437419779 

       [1] https://docs.openshift.com/container-platform/4.13/machine_management/control_plane_machine_management/cpmso-using.html#machineset-imds-options_cpmso-using 

      Linked XCMSTRAT JIRAs


            julim Ju Lim
            rh-ee-bchandra Balachandran Chandrasekaran
            2 Vote for this issue
            14 Start watching this issue