[openstack-dev] [neutron][metadata] Is there HTTP attack issue in metadata proxy functionality offered by reference implementation?

Mathieu Gagné mgagne at calavera.ca
Wed Nov 16 17:31:37 UTC 2016


On Wed, Nov 16, 2016 at 11:52 AM, Clint Byrum <clint at fewbar.com> wrote:
>
> IMO the HTTP metadata service and the way it works is one of the worst
> ideas we borrowed from EC2. Config drive (which I didn't like when I
> first saw it, but now that I've operated clouds, I love) is a simpler
> system and does not present any real surface area to the users.
>

Cannot agree more with you on that one.

--
Mathieu



More information about the OpenStack-dev mailing list