AWS::EC2::LaunchTemplate MetadataOptions - Amazon CloudFormation
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

AWS::EC2::LaunchTemplate MetadataOptions

The metadata options for the instance. For more information, see Instance metadata and user data in the Amazon EC2 User Guide.

MetadataOptions is a property of AWS::EC2::LaunchTemplate LaunchTemplateData.

Syntax

To declare this entity in your Amazon CloudFormation template, use the following syntax:

JSON

{ "HttpEndpoint" : String, "HttpProtocolIpv6" : String, "HttpPutResponseHopLimit" : Integer, "HttpTokens" : String, "InstanceMetadataTags" : String }

Properties

HttpEndpoint

Enables or disables the HTTP metadata endpoint on your instances. If the parameter is not specified, the default state is enabled.

Note

If you specify a value of disabled, you will not be able to access your instance metadata.

Required: No

Type: String

Allowed values: disabled | enabled

Update requires: No interruption

HttpProtocolIpv6

Enables or disables the IPv6 endpoint for the instance metadata service.

Default: disabled

Required: No

Type: String

Allowed values: disabled | enabled

Update requires: No interruption

HttpPutResponseHopLimit

The desired HTTP PUT response hop limit for instance metadata requests. The larger the number, the further instance metadata requests can travel.

Default: 1

Possible values: Integers from 1 to 64

Required: No

Type: Integer

Update requires: No interruption

HttpTokens

Indicates whether IMDSv2 is required.

  • optional - IMDSv2 is optional. You can choose whether to send a session token in your instance metadata retrieval requests. If you retrieve IAM role credentials without a session token, you receive the IMDSv1 role credentials. If you retrieve IAM role credentials using a valid session token, you receive the IMDSv2 role credentials.

  • required - IMDSv2 is required. You must send a session token in your instance metadata retrieval requests. With this option, retrieving the IAM role credentials always returns IMDSv2 credentials; IMDSv1 credentials are not available.

Default: If the value of ImdsSupport for the Amazon Machine Image (AMI) for your instance is v2.0, the default is required.

Required: No

Type: String

Allowed values: optional | required

Update requires: No interruption

InstanceMetadataTags

Set to enabled to allow access to instance tags from the instance metadata. Set to disabled to turn off access to instance tags from the instance metadata. For more information, see Work with instance tags using the instance metadata.

Default: disabled

Required: No

Type: String

Allowed values: disabled | enabled

Update requires: No interruption