Containers-roadmap: Feature Request: ECS-mediated Container Identity

Created on 13 Jul 2016  路  10Comments  路  Source: aws/containers-roadmap

Benefits of doing so are documented here

ECS

Most helpful comment

Offhand, the main things that we would need to be able to have feature parity with the EC2 method are:

  • An increasing timestamp of some sort. Ideally the time of the request to the metadata service, but that does increase burden.
  • An instance ID or some other kind of unique information that can be verified with a call to the external API.
  • This information available in a signed form that is _only_ available from within the container.

All 10 comments

Offhand, the main things that we would need to be able to have feature parity with the EC2 method are:

  • An increasing timestamp of some sort. Ideally the time of the request to the metadata service, but that does increase burden.
  • An instance ID or some other kind of unique information that can be verified with a call to the external API.
  • This information available in a signed form that is _only_ available from within the container.

An enthusiastic +1 to this request.

Also +1. This is a legitimately useful security feature.

+1

+1

+1

This would be awesome to have as it would bring feature parity between our EC2 and ECS deployments.

+1

+1
any update on this needed security feature ?

+1

Was this page helpful?
0 / 5 - 0 ratings