Skip to main content

Cloud Metadata Service Risk

Cloud metadata services can deliver workload credentials, so network and identity boundaries must stop unintended callers.

Threat definition

Cloud metadata services expose instance or workload information and can issue temporary cloud credentials. Server-side request forgery, compromised workloads, broad host networking, or weak hop controls can let an unintended caller retrieve and replay those credentials.

Assets and preconditions

Assets include cloud roles, tokens, instance identity documents, bootstrap data, and control-plane access. Preconditions include metadata reachability, a request primitive, excessive role permission, reusable tokens, or missing workload-level isolation.

Attack and containment

An attacker makes the workload request the metadata endpoint, obtains a credential, and uses it against cloud APIs. Limit metadata versions and paths, require supported session or hop protections, block unnecessary reachability, use narrow roles, bind workload identity, monitor issuance and use, and revoke the affected role or session.

Failure and residual risk

Network blocking can fail through proxies, alternate address families, host networking, or platform change. Short-lived credentials remain useful until expiry. A compromised workload can use its legitimate cloud role without stealing it.

Pomerium boundary

Pomerium can protect application routes but does not control a workload's local cloud metadata path or cloud IAM role. Operators must secure metadata access, workload identity, cloud policy, egress, detection, and containment.

Evaluation checklist

  • Which workloads can reach each metadata endpoint and version?
  • Which credentials and authority can the service issue?
  • Can server-side request forgery, a proxy, or host networking reach it?
  • Are roles narrow, credentials short-lived, and use attributable to one workload?
  • Can issuance and cloud API use be detected and contained?

Sources and further reading

Keep learning

Agentic AccessApplication and Service Access

Workload Identity

Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Credential Custody

Keep agent credentials isolated by user, task, audience, and tool and control storage, use, rotation, and revocation.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo